如何在Chrome中仅禁用eval循环内执行的debugger关键字
How to Disable Only the
debugger Keyword in Chrome DevTools for Obfuscated Scripts I’ve dealt with similar obfuscated scripts that spam debugger via nested eval and timers—here’s a practical, no-Chromium-compilation solution that targets only the debugger keyword without disabling all breakpoints or relying on ineffective "never stop here" rules:
Step-by-Step Solution: Hook Global Execution Functions to Strip debugger
The core idea is to intercept code passed to eval, setTimeout, setInterval, and Function (common ways obfuscated scripts run dynamic code) and remove any debugger; statements before execution.
Open Chrome DevTools and create a snippet
- Go to the Sources panel → Snippets tab.
- Click
New snippet, name it something likeRemoveDebugger.js.
Paste this code into the snippet
// Save original global functions const originalEval = window.eval; const originalSetTimeout = window.setTimeout; const originalSetInterval = window.setInterval; const originalFunction = window.Function; // Hook eval to strip debugger window.eval = function(code) { const modifiedCode = code.replace(/debugger;/g, ''); return originalEval.call(this, modifiedCode); }; // Hook setTimeout for string callbacks (some scripts pass code as strings) window.setTimeout = function(callback, delay, ...args) { if (typeof callback === 'string') { const modifiedCallback = callback.replace(/debugger;/g, ''); return originalSetTimeout.call(this, modifiedCallback, delay, ...args); } return originalSetTimeout.call(this, callback, delay, ...args); }; // Hook setInterval the same way window.setInterval = function(callback, delay, ...args) { if (typeof callback === 'string') { const modifiedCallback = callback.replace(/debugger;/g, ''); return originalSetInterval.call(this, modifiedCallback, delay, ...args); } return originalSetInterval.call(this, callback, delay, ...args); }; // Hook Function constructor (if scripts use new Function(...) to run code) window.Function = function(...args) { const body = args.pop(); const modifiedBody = body.replace(/debugger;/g, ''); args.push(modifiedBody); return originalFunction.apply(this, args); };Run the snippet before your target script loads
- Right-click the snippet → select
Run. - Now start your script (
node index.js)—the obfuscated code'sdebuggerstatements will be stripped before execution, so DevTools won't pause on them.
- Right-click the snippet → select
Why This Works (And Your Previous Methods Didn't)
- "Never stop here" fails because the
debuggeris in dynamically generated [VM] scripts—DevTools can't map these to fixed file positions to apply the rule. - Blackboxing is too broad and might block code you actually want to debug.
- This hook intercepts code at the moment it's about to be executed, regardless of how deeply nested the
eval/timers are, and only removes thedebuggerkeyword—leaving all other breakpoints and debug functionality intact.
Notes
- This is a temporary fix—you'll need to re-run the snippet if you refresh the page.
- If the obfuscated script uses variations like
debugger ;(with spaces), adjust the regex to/debugger\s*;/gfor better coverage. - If the script uses other rare dynamic execution methods, you can extend the hooks to cover those too.
内容的提问来源于stack exchange,提问作者Adrian Popescu
相关产品推荐
相关产品推荐

