The security model is broken. You can't securely do encryption in server side javascript.
The correct way is to create a (signed) package of your app so that it pulls in no external scripts or files. Makes updates a pain (no free auto-upgrades you get from the web) but makes the app a lot more difficult to attack.