
Security News
The Hidden Blast Radius of the Axios Compromise
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
@engine262/engine262
Advanced tools
An implementation of ECMA-262 in JavaScript
Goals
Non-Goals
This project is bound by a Code of Conduct.
Join us in #engine262:matrix.org.
While helping develop new features for JavaScript, I've found that one of the most useful methods of finding what works and what doesn't is being able to actually run code using the new feature. Babel is fantastic for this, but sometimes features just can't be nicely represented with it. Similarly, implementing a feature in one of the engines is a large undertaking, involving long compile times and annoying bugs with the optimizing compilers.
engine262 is a tool to allow JavaScript developers to have a playground where new features can be quickly prototyped and explored. As an example, adding do expressions to this engine is as simple as the following diff:
--- a/src/evaluator.mts
+++ b/src/evaluator.mts
@@ -232,6 +232,8 @@ export function* Evaluate(node) {
case 'GeneratorBody':
case 'AsyncGeneratorBody':
return yield* Evaluate_AnyFunctionBody(node);
+ case 'DoExpression':
+ return yield* Evaluate_Block(node.Block);
default:
throw new OutOfRange('Evaluate', node);
}
--- a/src/parser/ExpressionParser.mts
+++ b/src/parser/ExpressionParser.mts
@@ -579,6 +579,12 @@ export class ExpressionParser extends FunctionParser {
return this.parseRegularExpressionLiteral();
case Token.LPAREN:
return this.parseParenthesizedExpression();
+ case Token.DO: {
+ const node = this.startNode<ParseNode.DoExpression>();
+ this.next();
+ node.Block = this.parseBlock();
+ return this.finishNode(node, 'DoExpression');
+ }
default:
return this.unexpected();
}
This simplicity applies to many other proposals, such as optional chaining, pattern matching, the pipeline operator, and more. This engine has also been used to find bugs in ECMA-262 and test262, the test suite for conforming JavaScript implementations.
To run engine262 itself, a engine with support for recent ECMAScript features
is needed. Additionally, the CLI (bin/engine262.js) and test262 runner
(test/test262/test262.mts) require a recent version of Node.js.
You can install it from npm.
npm install @engine262/engine262
yarn install @engine262/engine262
pnpm install @engine262/engine262
If you install it globally, you can use the CLI like so:
$ engine262
Classic playground and Chrome Devtools style playground
Evaluate the file as a module.
Evaluate the given string and exit.
Run engine262 --list-features to see all ECMAScript features can be switched.
Do not expose $ and $262 global variable for test262 test suite.
Do not start an inspector.
By default engine262 will start an inspector on ws://localhost:9229/ (like Node.js with --inspector). See the Node.js guide for connecting.
Do not enable the preview feature in the inspector.
See the example.
npm run build and npm run watch will build and watch the build.
npm run test:test262 will run the test262 test suite. Run npm run test:test262 -- --help to see the test runner options.
npm start start the engine262 CLI.
npm run inspector start the website (debugging engine262 mainly happens here).
Many people and organizations have attempted to write a JavaScript interpreter in JavaScript much like engine262, with different goals. Some of them are included here for reference, though engine262 is not based on any of them.
FAQs
Implementation of ECMA-262 in JavaScript
We found that @engine262/engine262 demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.