Fuzzilli is a free, open-source tool for coverage-guided fuzzing of dynamic-language interpreters. It creates test programs in FuzzIL, its own intermediate language, then mutates them and translates them to JavaScript. Mutations can change data flow or operation parameters, generate or splice code, and combine programs from a corpus. The system includes a mutation fuzzer, script runner, corpus, runtime environment, minimizer, evaluator, and lifter. It sends repeated cases to a target engine in a read-eval-print-reset loop: the engine runs a script, resets, and waits for another. Instances can coordinate inside one process or over TCP across machines. Listed target directories include JavaScriptCore, JerryScript, QuickJS, QtJS, Serenity, SpiderMonkey, V8, XS, Duktape, and njs. Setup requires a supported JavaScript engine compiled with coverage instrumentation using clang 4.0 or later, then a Fuzzilli build with Swift Package Manager. Docker and Google Compute Engine tools are available. The project uses Apache-2.0 licensing and says it is not an officially supported Google product.
Who it is for
Fuzzilli suits people fuzzing dynamic-language interpreters, particularly JavaScript engine developers and researchers able to build an instrumented target. The project invites contributions, which require a Contributor License Agreement and GitHub pull-request review.
What is good
- Coverage-guided input generation, mutation, and hybrid methods.
- Supports multiple listed JavaScript engine targets.
- Instances can coordinate across machines over TCP.
- Docker and Google Compute Engine tooling is available.
What to know first
- Requires building an instrumented supported JavaScript engine.
- Requires Swift Package Manager to build Fuzzilli.
- Not an officially supported Google product.
Verdict
Fuzzilli offers a configurable fuzzing setup with multiple target engines and coordination options. Building it requires a compatible instrumented engine and the specified toolchain.
Fuzzilli plans and pricing
All plansCompared on fuzz testing software
- Input generation methods
- mutation, generation, hybrid
- Target types
- JavaScript programs and JavaScript engines/interpreters
- Coverage guidance
- Yes
- Crash triage
- Yes
- Execution mode
- hybrid
- Supported languages
- JavaScript
- CI/CD support
- Yes

