{"id":13454611,"url":"https://github.com/kurolabs/stegcloak","last_synced_at":"2025-05-14T04:07:27.126Z","repository":{"id":38883082,"uuid":"259692009","full_name":"KuroLabs/stegcloak","owner":"KuroLabs","description":"Hide secrets with invisible characters in plain text securely using passwords 🧙🏻‍♂️⭐","archived":false,"fork":false,"pushed_at":"2024-10-01T20:19:13.000Z","size":5592,"stargazers_count":3523,"open_issues_count":14,"forks_count":218,"subscribers_count":41,"default_branch":"master","last_synced_at":"2025-05-09T21:13:07.139Z","etag":null,"topics":["cipher","compression","cryptography","data-exfiltration","functional-programming","hacking","hacking-tool","hacking-tools","infosec","javascript","privacy","ramdajs","security","security-tools","steganography","stego"],"latest_commit_sha":null,"homepage":"https://stegcloak.surge.sh","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/KuroLabs.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2020-04-28T16:27:32.000Z","updated_at":"2025-05-09T08:40:27.000Z","dependencies_parsed_at":"2023-02-07T18:47:09.314Z","dependency_job_id":"6f298370-6be9-4ba8-9bc6-881bb94d1bc8","html_url":"https://github.com/KuroLabs/stegcloak","commit_stats":null,"previous_names":[],"tags_count":6,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/KuroLabs%2Fstegcloak","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/KuroLabs%2Fstegcloak/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/KuroLabs%2Fstegcloak/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/KuroLabs%2Fstegcloak/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/KuroLabs","download_url":"https://codeload.github.com/KuroLabs/stegcloak/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":254069476,"owners_count":22009557,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["cipher","compression","cryptography","data-exfiltration","functional-programming","hacking","hacking-tool","hacking-tools","infosec","javascript","privacy","ramdajs","security","security-tools","steganography","stego"],"created_at":"2024-07-31T08:00:55.851Z","updated_at":"2025-05-14T04:07:27.081Z","avatar_url":"https://github.com/KuroLabs.png","language":"JavaScript","funding_links":[],"categories":["Packages","Data Manipulation","Endpoint","Repository","\u003ca name=\"security\"\u003e\u003c/a\u003eSecurity and encryption","Useful","包"],"sub_categories":["Text","Authentication","Text/String","文本"],"readme":"\u003ch1 align=\"center\"\u003e\n  \u003cbr\u003e\n  \u003cimg src=\"assets/stegCloakIcon.svg\" alt=\"StegCloak\" width=\"100\"\u003e\n  \u003cbr\u003e\n  \u003cbr\u003e\n  \u003cspan\u003eStegCloak\u003c/span\u003e\n  \u003cbr\u003e\n  \u003cimg src=\"https://img.shields.io/npm/l/stegcloak?style=plastic\" /\u003e\n  \u003ca href=\"https://www.npmjs.com/package/stegcloak\"\u003e \u003cimg src=\"https://img.shields.io/npm/v/stegcloak?style=plastic\" /\u003e \u003c/a\u003e\n   \u003ca href=\"https://github.com/sindresorhus/awesome-nodejs\"\u003e\n  \u003cimg src=\"https://raw.githubusercontent.com/sindresorhus/awesome/main/media/badge.svg\" /\u003e\n  \u003c/a\u003e\n  \u003cimg src=\"https://img.shields.io/badge/code_style-standard-brightgreen.svg\" /\u003e\n  \u003cbr\u003e\n\u003c/h1\u003e\n\u003ch4 align=\"center\"\u003eThe Cloak of Invisibility for your texts\u003c/h4\u003e\n\n\u003cp align=\"justify\"\u003e\nStegCloak is a pure JavaScript steganography module designed in functional programming style, to hide secrets inside text by compressing and encrypting the secret before cloaking it with special unicode invisible characters. It can be used to safely watermark strings, invisible scripts on webpages, texts on social media or for any other covert communication. Completely invisible! See how it works in-depth in this Medium \u003ca href=\"https://blog.bitsrc.io/how-to-hide-secrets-in-strings-modern-text-hiding-in-javascript-613a9faa5787\"\u003earticle\u003c/a\u003e or watch our \u003ca href=\"https://www.youtube.com/watch?v=RBDqZwcGvQk\"\u003edemo\u003c/a\u003e to know what it does.\n\u003cp\u003e\n\n\u003ca href=\"https://standardjs.com\" style=\"position: absolute; top: 100px; right: 20px; padding: 0 0 20px 20px;\"\u003e\u003cimg src=\"https://cdn.rawgit.com/feross/standard/master/sticker.svg\" alt=\"JavaScript Standard Style\" width=\"80\" align=\"right\"\u003e\u003c/a\u003e\n\n## Features\n- Protect your invisible secret using passwords and HMAC integrity\n- Cryptographically secure by encrypting the invisible secret using AES-256-CTR.\n- Uses 6 Invisible characters in unicode characters that works everywhere in the web - Tweets, Gmail, WhatsApp, Telegram, Instagram, Facebook, and many more!\n- Maximum Compression to reduce the payload (LZ, Huffman).\n- Completely invisible, uses Zero Width Characters instead of white spaces or tabs.\n- Super fast! Hides the Wikipedia page-source for steganography (800 lines and 205362 characters) within a covertext of 3 words in under one second.\n- Hiding files in strings can be achieved by uploading the file to cloud and stegcloaking the link in the string\n- Written in pure functional style.\n- Usage - Available as an API module, a CLI and also a \u003ca href='https://stegcloak.surge.sh'\u003eWeb Interface\u003c/a\u003e (optimized with web workers). \n\n\u003cbr\u003e\n\n![StegCloak Demo](assets/stegcloak.gif)\n\n\n## Installing\n\nUsing npm,\n\n```bash\n$ npm install -g stegcloak\n```\nUsing npm (to use it locally in your program),\n\n```bash\n$ npm install stegcloak\n```\n\n## How it works\n\n\u003cimg src='assets/FlowDiagram.PNG'\u003e\n\n## CLI Usage\n\n### Hide\n\n```bash\n$ stegcloak hide\n```\nOptions:\n\n```\n  hide [options] [secret] [cover]\n\n  -fc, --fcover \u003cfile\u003e      Extract cover text from file\n  -fs, --fsecret \u003cfile\u003e     Extract secret text from file\n  -n, --nocrypt             If you don't need encryption (default: false)\n  -i, --integrity           If additional security of preventing tampering is needed (default: false)\n  -o, --output \u003coutput\u003e     Stream the results to an output file\n  -c, --config \u003cfile\u003e       Config file\n  -h, --help                display help for command\n\n```\n\n### Reveal\n\n```bash\n$ stegcloak reveal       \n```\nOptions:\n\n```\n  reveal [message]\n\n  -f, --file \u003cfile\u003e       Extract message from file\n  -cp, --clip             Copy message directly from clipboard\n  -o, --output \u003coutput\u003e   Stream the secret to an output file\n  -c, --config \u003cfile\u003e     Config file\n  -h, --help              display help for command\n```\n### Additional support\n\n- **STEGCLOAK_PASSWORD** environment variable, if set, will be used by default as password.\n\n- **Configuration file** support to configure StegCloak CLI and to avoid prompts. Read the config docs \u003ca href='https://github.com/KuroLabs/stegcloak/wiki/StegCloak-Configuration-File'\u003ehere.\u003c/a\u003e\n\n## API Usage\n\n```javascript\nconst StegCloak = require('stegcloak');\n\nconst stegcloak = new StegCloak(true, false);  // Initializes with encryption true and hmac false for hiding\n\n// These arguments are used only during hide\n\n// Can be changed later by switching boolean flags for stegcloak.encrypt and stegcloak.integrity\n\n```\n###### What's HMAC and do I need it?\n\n\u003cp align='justify'\u003e\nHMAC is an additional fingerprint security step taken towards tampering of texts and to verify if the message received was actually sent by the intended sender. If the data is sent through WhatsApp, Messenger or any social media platform, this is already taken care of! However, if you are using StegCloak in your program to safely transmit and retrieve, this option can be enabled and StegCloak takes care of it.\n\u003c/p\u003e\n\n### Hide\n\n###### `stegcloak.hide(secret, password, cover) -\u003e string`\n\n```javascript\nconst magic = stegcloak.hide(\"Voldemort is back\", \"mischief managed\", \"The WiFi's not working here!\");\n\n// Uses stegcloak.encrypt and stegcloak.integrity booleans for obfuscation\n\nconsole.log(magic);  // The WiFi's not working here!\n```\n\n### Reveal\n\n###### `stegcloak.reveal(data, password) -\u003e string`\n\n```javascript\nconst secret = stegcloak.reveal(magic, \"mischief managed\");\n\n// Automatically detects if encryption or integrity checks were done during hide and acts accordingly\n\nconsole.log(secret); // Voldemort is back\n```\n\nThis amazing [blog](https://iwantmore.pizza/posts/zwc-fingerprint.html) by [Francesco Soncina](https://twitter.com/phraaaaaaa) shows how you could use the StegCloak API to watermark any text on your website.\n\n#### Important\n\u003cp align='justify'\u003e\nStegCloak doesn't solve the Alice-Bob-Warden problem, it's powerful only when people are not looking for it and it helps you achieve that really well, given its invisible properties around the web! It could be safely used for watermarking in forums, invisible tweets, social media etc. Please don't use it when you know there's someone who is actively sniffing your data - looking at the unicode characters through a data analysis tool. In that case, even though the secret encoded cannot be deciphered, the fact lies that the Warden (middle-man) knows some secret communication took place, because he would have noticed an unusual amount of special invisible characters.\n\u003c/p\u003e\n\n## Contributing\n\nPull requests are welcome. For major changes, please open an issue first to discuss what you would like to change.\n\n## License\n\n[MIT](https://github.com/KuroLabs/stegcloak/blob/master/LICENSE) - Copyright (c) 2020 [Jyothishmathi CV](https://github.com/JyothishmathiCV), [Kandavel A](https://github.com/AK5123), [Mohanasundar M](https://github.com/mohanpierce99)\n\n## Acknowledgements\nThe StegCloak logo was designed by \u003ca href=\"https://www.flaticon.com/authors/smashicons\" title=\"Smashicons\"\u003eSmashicons\u003c/a\u003e.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkurolabs%2Fstegcloak","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fkurolabs%2Fstegcloak","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkurolabs%2Fstegcloak/lists"}