{"id":28673298,"url":"https://github.com/spyboy-productions/obfuxtreme","last_synced_at":"2025-09-17T23:47:18.434Z","repository":{"id":280202509,"uuid":"936845397","full_name":"spyboy-productions/ObfuXtreme","owner":"spyboy-productions","description":"ObfuXtreme is an advanced Python obfuscation tool designed to bypass antivirus detection and remain undetectable on VirusTotal.","archived":false,"fork":false,"pushed_at":"2025-08-08T21:02:37.000Z","size":405,"stargazers_count":156,"open_issues_count":0,"forks_count":11,"subscribers_count":4,"default_branch":"main","last_synced_at":"2025-08-08T23:23:02.448Z","etag":null,"topics":["aes-encryption","anti-debugging","anti-reversing","bypass-antivirus","bypass-av","obfuscate","obfuscate-scripts","obfuscation","obfuscator","polymorphic-code","python-encryption","python-obfuscate","python-obfuscator","undetectable-obfuscation","virustotal-bypass"],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"agpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/spyboy-productions.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2025-02-21T19:40:20.000Z","updated_at":"2025-08-08T21:02:40.000Z","dependencies_parsed_at":"2025-03-02T00:17:59.845Z","dependency_job_id":"f3cd072d-1e41-4a01-bebb-a7a0cd1c45b8","html_url":"https://github.com/spyboy-productions/ObfuXtreme","commit_stats":null,"previous_names":["spyboy-productions/obfuxtreme"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/spyboy-productions/ObfuXtreme","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spyboy-productions%2FObfuXtreme","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spyboy-productions%2FObfuXtreme/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spyboy-productions%2FObfuXtreme/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spyboy-productions%2FObfuXtreme/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/spyboy-productions","download_url":"https://codeload.github.com/spyboy-productions/ObfuXtreme/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spyboy-productions%2FObfuXtreme/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":275685401,"owners_count":25509530,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-09-17T02:00:09.119Z","response_time":84,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["aes-encryption","anti-debugging","anti-reversing","bypass-antivirus","bypass-av","obfuscate","obfuscate-scripts","obfuscation","obfuscator","polymorphic-code","python-encryption","python-obfuscate","python-obfuscator","undetectable-obfuscation","virustotal-bypass"],"created_at":"2025-06-13T20:09:47.673Z","updated_at":"2025-09-17T23:47:18.422Z","avatar_url":"https://github.com/spyboy-productions.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003ch4 align=\"center\"\u003e If you find this GitHub repo useful, please consider giving it a star! ⭐️ \u003c/h4\u003e \n\u003cp align=\"center\"\u003e\n    \u003ca href=\"https://spyboy.in/twitter\"\u003e\n      \u003cimg src=\"https://img.shields.io/badge/-TWITTER-black?logo=twitter\u0026style=for-the-badge\"\u003e\n    \u003c/a\u003e\n    \u0026nbsp;\n    \u003ca href=\"https://spyboy.in/\"\u003e\n      \u003cimg src=\"https://img.shields.io/badge/-spyboy.in-black?logo=google\u0026style=for-the-badge\"\u003e\n    \u003c/a\u003e\n    \u0026nbsp;\n    \u003ca href=\"https://spyboy.blog/\"\u003e\n      \u003cimg src=\"https://img.shields.io/badge/-spyboy.blog-black?logo=wordpress\u0026style=for-the-badge\"\u003e\n    \u003c/a\u003e\n    \u0026nbsp;\n    \u003ca href=\"https://spyboy.in/Discord\"\u003e\n      \u003cimg src=\"https://img.shields.io/badge/-Discord-black?logo=discord\u0026style=for-the-badge\"\u003e\n    \u003c/a\u003e\n  \n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cimg width=\"20%\" src=\"https://github.com/spyboy-productions/ObfuXtreme/blob/main/Image/logo_ObfuXtreme.jpg\" /\u003e\n\u003c/p\u003e\n\n\nObfuXtreme is an advanced Python obfuscation tool designed to bypass antivirus detection and remain undetectable on VirusTotal.\n\n- **AES-256 Encryption** with CBC mode\n- **Abstract Syntax Tree (AST)** manipulation\n- **Polymorphic Code Generation**\n- **Zlib Compression** + **Marshal Serialization**\n\n---\n\n\u003e [!CAUTION] \n\u003e **Please use this responsibly and ethically.**\n\u003e \u003ch4\u003e DISCLAIMER \u003c/h4\u003e \n\u003e ObfuXtreme is a Proof of Concept (PoC) Tool created strictly for educational and research purposes. It is designed to demonstrate advanced Python obfuscation techniques.  \nWhile this tool showcases its effectiveness by being undetectable on VirusTotal, it is NOT intended for malicious use. Using ObfuXtreme to obfuscate malware, bypass security measures, or engage in any unethical activities is strictly prohibited.  \n\n#### **Responsibility \u0026 Ethics**  \n- Cybersecurity professionals and developers can use this tool to **understand, analyze, and defend against** similar obfuscation techniques used by attackers.  \n- The **developer does not condone** nor take responsibility for any misuse of this tool. Users are solely accountable for how they apply it.  \n- **Always comply with local laws and ethical guidelines** when using this tool.  \n\nBy using ObfuXtreme, `you acknowledge that you understand these terms and accept full responsibility for your actions`.  \n\n### ✨ Feature \n\n| Feature | Found? | Notes |\n|---------|--------|-------|\n| **Military-Grade Encryption** | ✅ | Uses **AES-256-CBC** for encryption. |\n| **AES-256-CBC with per-build random keys** | ✅ | Generates a new **32-byte key** (`self.aes_key = os.urandom(32)`) and **16-byte IV** (`self.iv = os.urandom(16)`) per build. |\n| **AST-Level Transformations** | ✅ | Implements **Variable Renaming, Control Flow Flattening, and String Encryption** using `ast.NodeTransformer`. |\n| **Variable Renaming** | ✅ | Uses a hashing method (`shake_128`) to obfuscate variable names. |\n| **Control Flow Flattening** | ✅ | Implements state-based execution in `ControlFlowFlattener`. |\n| **String Encryption** | ✅ | Encrypts string literals with AES before execution. |\n| **Anti-Analysis Protections** | ✅ | Includes **Debugger Detection, Memory Bombardment, and Environment Checks**. |\n| **Debugger Detection** | ✅ | `_anti_debug()` exits if a debugger is detected (`sys.gettrace()` or `IsDebuggerPresent`). |\n| **Memory Bombardment** | ❌ | No evidence of excessive memory usage or process exhaustion techniques. |\n| **Environment Checks** | ✅ | Uses OS-based debugger detection. |\n| **Self-Destruct Mechanism** | ✅ | Implements **Tamper detection with SHA-3 integrity checks** (used in `_decrypt_str` with exception handling). |\n| **Stealth Operation** | ✅ | Uses **silent failure modes** (returns empty string if decryption fails) and **exception handling**. |\n| **Cross-Platform** | ✅ | Designed for **Windows, Linux, and macOS** using standard Python and PyCryptodome. |\n\n---\n\n## VirusTotal Scans\n\n\u003cp align=\"center\"\u003e \u003cstrong\u003eWithout ObfuXtreme\u003c/strong\u003e\u003cbr\u003e \u003cimg width=\"90%\" src=\"https://github.com/spyboy-productions/ObfuXtreme/blob/main/Image/without_ObfuXtreme.png\" alt=\"VirusTotal scan without ObfuXtreme\" /\u003e \u003c/p\u003e \n\u003cp align=\"center\"\u003e \u003cstrong\u003eWith ObfuXtreme\u003c/strong\u003e\u003cbr\u003e \u003cimg width=\"90%\" src=\"https://github.com/spyboy-productions/ObfuXtreme/blob/main/Image/with_ObfuXtreme.png\" alt=\"VirusTotal scan with ObfuXtreme\" /\u003e \u003c/p\u003e\n\n\n## 📖 Installation\n```bash\ngit clone https://github.com/spyboy-productions/ObfuXtreme.git\n```\n```\ncd ObfuXtreme\n```\n```\npip install -r requirements.txt\n```\n```\npython ObfuXtreme.py \u003cyour_script.py\u003e\n```\n`To Run Light version With No External requirements:`\n```\npython light_ObfuXtreme.py \u003cyour_script.py\u003e\n```\n## 🔥 Usage\n\nTo obfuscate a Python script, run:\n\nExample:\n\n`python ObfuXtreme.py test.py`\n\nThis will generate an obfuscated file named obfuscated.py that contains the encrypted and protected version of your script.\n\n🛠️ Running the Obfuscated Script\n\nSimply run:\n\n`python obfuscated.py`\n\n### To do:\n1. add new module that Works only on the original machine.\n2. add new module that ask for password.\n3. add option to convert to .exe file after obfuscation.\n\n\u003ch4 align=\"center\"\u003e If you find this GitHub repo useful, please consider giving it a star! ⭐️ \u003c/h4\u003e \n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fspyboy-productions%2Fobfuxtreme","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fspyboy-productions%2Fobfuxtreme","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fspyboy-productions%2Fobfuxtreme/lists"}