Briefing

Mochi.js: Bun-Native Browser Automation Framework for WAF and Captcha Evasion

ux
by ccheshirecat ·

Use Mochi.js to bypass WAFs and captchas in automated testing.

What to do now

Integrate Mochi.js into your automation pipeline to improve WAF evasion.

Summary

Mochi.js is a new, Bun‑native, raw‑CDP browser automation framework that focuses on consistency and measured parity with regular traffic, rather than cosmetic client‑side probing. It is designed to bypass WAFs, captchas, and most defense mechanisms by using a probe manifest built from real‑world WAF analysis, solving Turnstile interstitials automatically, and providing low fingerprint scores against FingerprintJS Pro. Mochi.js is open‑source under the MIT license, fully documented, and includes live benchmark data showing it can evade detection on Linux datacenter IPs.

Unlike traditional automation tools that rely on deception or client‑side line‑by‑line probes, Mochi.js operates as a glass‑box, respecting hardware realities and avoiding unnecessary lies. It supports Bun, raw CDP, and can be integrated into existing automation pipelines to improve WAF evasion and captcha handling.

The release is aimed at developers and security researchers who need reliable, non‑deceptive automation for testing and penetration testing, and it challenges the current paradigm of bot detection by providing a transparent, data‑driven approach.

Key changes

  • Built on Bun‑native raw‑CDP for high performance
  • Designed to bypass WAFs and captchas using real‑world probe data
  • Solves Turnstile interstitials automatically
  • Provides low fingerprint scores against FingerprintJS Pro
  • Open‑source MIT license with full documentation and benchmarks

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting