{"_id":"@callowayisweird/gmod-protect","_rev":"4-a3f2ed4c9e1e367b7a32b8d87c4ff0fc","name":"@callowayisweird/gmod-protect","dist-tags":{"latest":"1.0.3"},"versions":{"1.0.0":{"name":"@callowayisweird/gmod-protect","version":"1.0.0","keywords":["gmod","garrys-mod","lua","bytecode","compiler","obfuscation","protection","glua"],"author":{"name":"callowayisweird"},"license":"SEE LICENSE IN LICENSE","_id":"@callowayisweird/gmod-protect@1.0.0","maintainers":[{"name":"callowayisweird","email":"henrythegamerguy62@gmail.com"}],"homepage":"https://github.com/callowayisweird/gmod-protect#readme","bugs":{"url":"https://github.com/callowayisweird/gmod-protect/issues"},"bin":{"gprotect":"dist/cli.cjs"},"dist":{"shasum":"98cd5e734f0faa5e94016e7e4b96732f41090428","tarball":"https://registry.npmjs.org/@callowayisweird/gmod-protect/-/gmod-protect-1.0.0.tgz","fileCount":10,"integrity":"sha512-CikkJCBHagqwDu1oLPaNDTetm5f915NmlUdc6aoVM4VkkL8Zffidrn8MGRdLNZsZX4kqT3iaEJ6OBu08m3TsOQ==","signatures":[{"sig":"MEUCIHipARgQvJeqHYwh7eY+U2aB9ktcJXVQJhG5YzGLq6K1AiEAm1i5+NCu6RJN0E2yBqDikJwfsgFIEjuKKEnZNrLnskk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1047158},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","gitHead":"9c89dddda39b0a5232b291af6a764f7258c92ef7","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"callowayisweird","email":"henrythegamerguy62@gmail.com"},"repository":{"url":"git+https://github.com/callowayisweird/gmod-protect.git","type":"git"},"_npmVersion":"10.8.2","description":"Compile Garry's Mod Lua into custom bytecode with a randomized VM runtime — makes addon source unreadable and undecompilable.","directories":{},"_nodeVersion":"20.20.1","dependencies":{"commander":"^12.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^2.1.0","typescript":"^5.6.0"},"_npmOperationalInternal":{"tmp":"tmp/gmod-protect_1.0.0_1774791775999_0.35341534698837185","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@callowayisweird/gmod-protect","version":"1.0.1","keywords":["gmod","garrys-mod","lua","bytecode","compiler","obfuscation","protection","glua"],"author":{"name":"callowayisweird"},"license":"SEE LICENSE IN LICENSE","_id":"@callowayisweird/gmod-protect@1.0.1","maintainers":[{"name":"callowayisweird","email":"henrythegamerguy62@gmail.com"}],"homepage":"https://github.com/callowayisweird/gmod-protect#readme","bugs":{"url":"https://github.com/callowayisweird/gmod-protect/issues"},"bin":{"gprotect":"dist/cli.cjs"},"dist":{"shasum":"7b48e6bf8f20f452ca5c54d3f3962a86af92a2f5","tarball":"https://registry.npmjs.org/@callowayisweird/gmod-protect/-/gmod-protect-1.0.1.tgz","fileCount":10,"integrity":"sha512-3bkkoY8pb/vw+d3s023AoGsQEXdLOL9wPA9jvNwOvaegWpAyUs0k5U30Aw5Je5Xjso1RYx5qxjYhFf3BgNuIFw==","signatures":[{"sig":"MEUCIQDaozBQazNwZsIw3H8IL9Cuw2zOJosoDS/8/5GcJKuMCAIgKJexC2JTwmaiAGPvYLQS36VDixzB6ncfTGqe4ABifgs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":933818},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","gitHead":"7d1958c03a046c6297ac96f148a20bb1f755575f","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"callowayisweird","email":"henrythegamerguy62@gmail.com"},"repository":{"url":"git+https://github.com/callowayisweird/gmod-protect.git","type":"git"},"_npmVersion":"10.8.2","description":"Compile Garry's Mod Lua into custom bytecode with a randomized VM runtime — makes addon source unreadable and undecompilable.","directories":{},"_nodeVersion":"20.20.1","dependencies":{"commander":"^12.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","terser":"^5.46.1","vitest":"^2.1.0","typescript":"^5.6.0"},"_npmOperationalInternal":{"tmp":"tmp/gmod-protect_1.0.1_1774792318364_0.8258578506885257","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@callowayisweird/gmod-protect","version":"1.0.2","keywords":["gmod","garrys-mod","lua","bytecode","compiler","obfuscation","protection","glua"],"author":{"name":"callowayisweird"},"license":"SEE LICENSE IN LICENSE","_id":"@callowayisweird/gmod-protect@1.0.2","maintainers":[{"name":"callowayisweird","email":"henrythegamerguy62@gmail.com"}],"homepage":"https://github.com/callowayisweird/gmod-protect#readme","bugs":{"url":"https://github.com/callowayisweird/gmod-protect/issues"},"bin":{"gprotect":"dist/cli.cjs"},"dist":{"shasum":"ae449f5c265630048246d59a0d9589111e9f208b","tarball":"https://registry.npmjs.org/@callowayisweird/gmod-protect/-/gmod-protect-1.0.2.tgz","fileCount":9,"integrity":"sha512-Xs2MGH4ChbwsN1q1TI5iEFqvh6P3VFDYnUvcScnabt/24cZK1I4Am8pyMtCTasWKJ14P1cH4xWvbmHUsU8ZYOw==","signatures":[{"sig":"MEQCIE5k3Uu5b0awzw1TL6Hq0/7qoiptXILHcu6h3Q24lGCeAiBNtKkovqyD7wvyNIYNlz7c4MhgXi/IqElBda3DeU5tcg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":918690},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","gitHead":"0daf1655dc7f76bc4a6ba39c2ec60d4e6fcafebb","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"callowayisweird","email":"henrythegamerguy62@gmail.com"},"repository":{"url":"git+https://github.com/callowayisweird/gmod-protect.git","type":"git"},"_npmVersion":"10.8.2","description":"Compile Garry's Mod Lua into custom bytecode with a randomized VM runtime — makes addon source unreadable and undecompilable.","directories":{},"_nodeVersion":"20.20.1","dependencies":{"commander":"^12.1.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","terser":"^5.46.1","vitest":"^2.1.0","typescript":"^5.6.0"},"_npmOperationalInternal":{"tmp":"tmp/gmod-protect_1.0.2_1774792810411_0.9755161832927701","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"@callowayisweird/gmod-protect","version":"1.0.3","description":"Compile Garry's Mod Lua into custom bytecode with a randomized VM runtime — makes addon source unreadable and undecompilable.","type":"module","main":"dist/index.js","types":"dist/index.d.ts","bin":{"gprotect":"dist/cli.cjs"},"scripts":{"build":"tsup","dev":"tsup --watch","test":"vitest run","test:watch":"vitest","prepublishOnly":"npm run build"},"keywords":["gmod","garrys-mod","lua","bytecode","compiler","obfuscation","protection","glua"],"author":{"name":"callowayisweird"},"license":"SEE LICENSE IN LICENSE","repository":{"type":"git","url":"git+https://github.com/callowayisweird/gmod-protect.git"},"dependencies":{"commander":"^12.1.0"},"devDependencies":{"terser":"^5.46.1","tsup":"^8.3.0","typescript":"^5.6.0","vitest":"^2.1.0"},"_id":"@callowayisweird/gmod-protect@1.0.3","gitHead":"9e90a6aa8777f00b6c18d758444acc6892f3eb35","bugs":{"url":"https://github.com/callowayisweird/gmod-protect/issues"},"homepage":"https://github.com/callowayisweird/gmod-protect#readme","_nodeVersion":"20.20.1","_npmVersion":"10.8.2","dist":{"integrity":"sha512-E6TGzOMx6No8G2uSYYYuoon4eHxFYb7/6OH82+TJ6+5nyqtf8wXJqukY0zu88y6Mwuzkqz+SETum8znCTPY3zA==","shasum":"16fab466635905b390d1d2d187d0b385b48954a4","tarball":"https://registry.npmjs.org/@callowayisweird/gmod-protect/-/gmod-protect-1.0.3.tgz","fileCount":9,"unpackedSize":918917,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCaWsbtxXT5JWk9kmShxvPCAASGwfcXPsChzus6kkB0WQIhAOMgRGmGElf4+iCwHeRj8SKvruAxD6vspy53dU5+qWU3"}]},"_npmUser":{"name":"callowayisweird","email":"henrythegamerguy62@gmail.com"},"directories":{},"maintainers":[{"name":"callowayisweird","email":"henrythegamerguy62@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/gmod-protect_1.0.3_1774793506234_0.8345313111437502"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-29T13:42:55.941Z","modified":"2026-03-29T14:11:46.571Z","1.0.0":"2026-03-29T13:42:56.220Z","1.0.1":"2026-03-29T13:51:58.558Z","1.0.2":"2026-03-29T14:00:10.626Z","1.0.3":"2026-03-29T14:11:46.438Z"},"bugs":{"url":"https://github.com/callowayisweird/gmod-protect/issues"},"author":{"name":"callowayisweird"},"license":"SEE LICENSE IN LICENSE","homepage":"https://github.com/callowayisweird/gmod-protect#readme","keywords":["gmod","garrys-mod","lua","bytecode","compiler","obfuscation","protection","glua"],"repository":{"type":"git","url":"git+https://github.com/callowayisweird/gmod-protect.git"},"description":"Compile Garry's Mod Lua into custom bytecode with a randomized VM runtime — makes addon source unreadable and undecompilable.","maintainers":[{"name":"callowayisweird","email":"henrythegamerguy62@gmail.com"}],"readme":"# gmod-protect\n\n**The most advanced free addon protection for Garry's Mod.**\n\nYour source code is your livelihood. Stop giving it away. gmod-protect compiles your GLua into military-grade obfuscated bytecode that no existing tool can read, decompile, or reverse. One command. Zero cost. No subscriptions. No servers. No single point of failure.\n\n---\n\n## Install. Protect. Ship.\n\n```bash\nnpm install -g @callowayisweird/gmod-protect\n\ngprotect build ./my-addon/lua/ --addon-name my_addon\n```\n\nDone. Your entire addon is now protected. The output folder is ready to upload to GModStore, Workshop, or anywhere else.\n\nAnyone who opens your files sees this:\n\n```lua\nreturn \"R1BCAQEAAgBylU5t7IWYULiylgYAeE8plleRNYlkj+3agfuRVL/M1rvQeKP0sBH...\"\n```\n\n---\n\n## Before & After\n\nYour code:\n```lua\nfunction MyAddon:Initialize()\n    self.config = loadConfig(\"settings.json\")\n    hook.Add(\"Think\", \"MyAddon_Think\", function()\n        for _, ply in ipairs(player.GetAll()) do\n            self:ProcessPlayer(ply)\n        end\n    end)\nend\n```\n\nAfter protection:\n- Source code is **gone**. Replaced by custom bytecode running in a proprietary virtual machine.\n- Every string — `\"Think\"`, `\"settings.json\"`, `\"MyAddon\"` — is **encrypted and fragmented**. Not a single readable string exists in the output.\n- The control flow is **flattened** into an unrecognizable state machine. Loops, branches, and function structure are destroyed.\n- Arithmetic and constants are **transformed** into equivalent but unrecognizable sequences.\n- **Dead code paths** and **decoy instructions** are woven throughout, indistinguishable from real logic.\n- Each build generates a **completely unique instruction set**. Every addon has its own.\n\nNo Lua decompiler works. No hex editor helps. No existing tool on earth can read this.\n\n---\n\n## 10-Layer Protection Pipeline\n\nEvery file passes through ten independent security layers:\n\n| # | Layer | What it does |\n|---|-------|-------------|\n| 1 | **String fragmentation** | Shatters every string into random pieces reassembled at runtime |\n| 2 | **Opaque predicates** | Wraps real code in mathematically hard-to-solve conditions |\n| 3 | **Control flow flattening** | Destroys if/else/loop structure into a flat state machine |\n| 4 | **Arithmetic metamorphosis** | Transforms math operations into equivalent unrecognizable sequences |\n| 5 | **Constant encoding** | Numbers are computed at runtime from randomized operands |\n| 6 | **Dead code injection** | Inserts realistic fake code blocks that can't be automatically removed |\n| 7 | **Instruction noise** | Interleaves decoy instructions between real operations |\n| 8 | **String encryption** | All string data encrypted with per-build derived keys |\n| 9 | **Instruction set randomization** | Every build creates a unique set of virtual machine opcodes |\n| 10 | **Anti-interception runtime** | Native C module prevents bytecode from being captured via Lua hooks |\n\nA typical file goes from **37 instructions to 230+**. All variable names, comments, and formatting are permanently erased.\n\n---\n\n## How Developers Use It\n\n### 1. Develop your addon normally\n\n```\nmy-awesome-addon/\n└── lua/\n    ├── autorun/server/init.lua\n    ├── my_addon/sv_core.lua\n    ├── my_addon/sv_config.lua\n    └── my_addon/cl_hud.lua\n```\n\n### 2. Protect it\n\n```bash\ngprotect build ./my-awesome-addon/lua/ --addon-name my_addon -o ./release\n```\n\n### 3. Ship it\n\nUpload the `release/` folder. That's your addon.\n\n```\nrelease/\n├── lua/\n│   ├── autorun/server/my_addon_loader.lua    # Auto-generated loader\n│   ├── my_addon/                             # Same structure as your original\n│   │   ├── sv_core.lua                       # Protected (bytecode)\n│   │   ├── sv_config.lua                     # Protected (bytecode)\n│   │   └── config/settings.lua               # Excluded (plain Lua, if using -e)\n│   └── bin/gmsv_gprotect_*.dll               # Runtime (all platforms)\n```\n\nThe output mirrors your original directory structure exactly. Same paths, same filenames — the only difference is file contents.\n\n**Instructions for your buyers:**\n> 1. Extract to `garrysmod/addons/`\n> 2. Place the `.dll` files in `garrysmod/lua/bin/`\n> 3. Restart your server\n\nThat's it. The DLL is universal — one runtime for all gprotect addons. Install it once, every protected addon works.\n\n---\n\n## Developer Notes\n\n- **Re-protect on every release.** Each build generates a completely new instruction set. Old builds can't be reused.\n- **Keep your source code safe.** Protection is one-way. There is no \"unprotect\" command. If you lose your source, it's gone forever.\n- **Test before shipping.** Always verify the protected build on a local server.\n- **Config files** that buyers need to edit should be excluded with `-e`. They'll be copied as plain Lua.\n\n---\n\n## Supported GLua\n\nFull Lua 5.1 + all GMod extensions:\n\n- `//` and `/* */` comments\n- `!`, `!=`, `&&`, `||` operators\n- `continue` keyword\n- Tables, closures, upvalues, varargs\n- Method calls (`ply:Nick()`, `timer.Simple(...)`)\n- Numeric and generic `for` loops\n- Multiple return values\n- Nested functions and scoping\n\n---\n\n## CLI\n\n```bash\ngprotect build <dir>                              # Protect entire addon\ngprotect build <dir> -o ./release                 # Custom output directory\ngprotect build <dir> -n my_addon                  # Custom addon name\ngprotect build <dir> -e \"config/*\" \"sh_*.lua\"     # Exclude files (copied as plain Lua)\ngprotect build <dir> -e \"**/config.lua\"           # Exclude by pattern\ngprotect build <dir> --no-obfuscate               # Bytecode only, skip obfuscation\ngprotect compile <file.lua>                       # Protect a single file\n```\n\n### Excluding files\n\nUse `-e` / `--exclude` to keep files as readable Lua. Excluded files are copied to the output as-is — not protected, not removed. This is for config files, shared code, or anything buyers need to read or edit.\n\n```bash\n# Exclude all config files and shared code\ngprotect build ./lua -e \"config/*\" \"sh_*.lua\" \"**/settings.lua\"\n\n# Exclude entire directories\ngprotect build ./lua -e \"my_addon/config/**\"\n```\n\nGlob patterns: `*` matches within a directory, `**` matches across directories, `?` matches a single character. Matching is case-insensitive.\n\n---\n\n## Why Not LegionDRM?\n\n| | LegionDRM | gmod-protect |\n|---|---|---|\n| **Cost** | Paid subscription | Free forever |\n| **Dependency** | Their servers go down = your addon breaks | Runs 100% locally |\n| **Runtime** | Per-addon system | One universal DLL for all addons |\n| **Setup** | Account, API keys, integration | `npm install`, one command |\n| **Source required?** | Send your code to their servers | Never leaves your machine |\n| **Development** | Closed, opaque | Actively maintained, community feedback welcome |\n\n---\n\n## FAQ\n\n**Can someone reverse-engineer the protected code?**\nThe bytecode runs in a custom virtual machine with a unique instruction set per build. There is no existing decompiler, disassembler, or analysis tool that can read this format. Building one from scratch would require significant reverse engineering of the compiled native runtime — far beyond the capability of typical GMod script kiddies.\n\n**Is the runtime DLL safe?**\nThe runtime is a standard GMod binary module (like mysqloo or chttp). It follows the same `GMOD_MODULE_OPEN` / `GMOD_MODULE_CLOSE` pattern. It reads protected files, decrypts them internally, and executes them in a sandboxed virtual machine.\n\n**Does this protect client-side code?**\nNo. The runtime DLL runs on the server. Clients don't have it and you can't make them install it. Protect your server-side code — that's where your addon logic, database access, permissions, and API keys live. Client-side code (HUD rendering, UI elements) is cosmetic and not worth protecting.\n\n**Does Workshop upload work?**\nYes. The output is standard `.lua` files in a standard addon folder structure. Workshop sees normal Lua files.\n\n**What if two addons both use gmod-protect?**\nThey both work. The runtime DLL is universal — it handles any number of protected addons simultaneously, each with their own unique instruction set.\n\n---\n\n## V1 Limitations\n\n- No coroutines\n- No debug library (intentional)\n- No `goto` statement\n- No metatables on non-table types\n\n---\n\n## License\n\nCopyright (c) 2026 callowayisweird. All rights reserved.\n\nThis software is provided as a free tool. Redistribution of the source code is not permitted.\n","readmeFilename":"README.md"}