They do nice stuff, like hiding some of your strings, other literals and random predicates inside an encrypted string. This is decrypted and eval'd at runtime using the text of the decrypt function as a parameter i.e, you can't beautify it otherwise it stop working. The random predicates are merged within your code for instance: it appends a `&& somePredicateThatReturnsTrue(someOtherRandomValue)` to ifs conditions. It makes it really hard to figure out what is happening.
So no webpack plugin, I guess :)
[1] I'm assuming it's written in JS. It might not, of course.
This is decrypted and eval'd at runtime
Most(all?) string-based obfuscators can be bypassed by simply replacing eval with a logging eval implementation.
var oldEval = eval; eval = function(str){console.log(str);oldEval(str)};
A similar patch to the Function constructor can bypass the other easy dynamic code generation code path.If at some point, a string needs to be evaluated as code, then it's possible to intercept that code and output it.