We assume attackers have fully deobfuscated our JS bundle and design the detection around that

From Bytecode to CFGs inside our online WebAssembly reverse engineering tool

Building a Wasm-in-Wasm Virtualizer (with JIT decrypted paged memory)