Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Mochi.js: bun-native high-fidelity browser automation library

Details

External ID
48075059
Source
HN
Company
—
Product
Mochi.js: bun-native high-fidelity browser automation library
Website domain
mochijs.com
Launched
May 9, 2026
Cohort
—
Upvotes
47
Upvotes percentile
0.8336025848142165
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

Hi HN,I’m sharing mochi.js (https://github.com/0xchasercat/mochi), a Bun-native, raw-CDP browser automation framework. It's designed to make programmatic browser use more effective by focusing on consistency and measured parity with regular traffic, purely from the JS layer, against stock Chromium.The most common forms of browser automation focus heavily on client-side line by line probes, which are mostly cosmetic. This makes people feel better but it doesn't have much relevance to actual WAF or anti-automation defences.Mochi.js focuses on what actually matters, allowing you to get past captchas, WAF's and most defence mechanisms. In fact, in some cases it actually outperforms chromium forks simply by virtue of not having to lie.The foundation is built on a probe manifest based on analyzing several WAF's and trying to cover most of the ground that matters, and from there building upwards while ensuring every decision is backed by data. Solves turnstile/interstitial automatically, single digit fpjs suspect score, very good client-side results, though browserscan and a few others are known limitations that are fundamentally conflicting with what WAF's probe for.I'll be here if anyone wants to discuss the details, check out the docs and github. It's completely free and open source, MIT, strictly no relationship to any proprietary products whatsoever. No affiliation to patched chromium forks, or SaaS.But I also want to talk about why I built this, because the current paradigm of "bot detection" is fundamentally broken.Traditionally they would probably try to label my repository a malicious tool, or at best, a grey hat one.Let's take Turnstile for example, If you attach a debugger to see what data they are extracting from your hardware, their script intentionally self-destructs. When they try to extract your data—acting as a guest on your silicon, using your electricity, without asking, the industry calls it "Security."But if you write a script to control exactly what data your own hardware emits, refusing to provide the data they have no right to ask for, you are suddenly labeled a "Malicious Actor" engaged in "Bot Evasion."I find it absurd we let ourselves put up with this, and the stance of the bot-evasion community only makes them feel more able to take a higher moral ground.I have built a library that respects my hardware's reality. If that breaks your security model, that's because your security model relies on trespassing and secrecy. I stopped apologizing. Who's next?Mochi is the exact opposite of WAF opacity. It is a glass box. It is MIT-licensed. The entire DAG, fingerprint manifest schema, harvesting process, is documented. We even commit our live benchmarks to the public record (mochi on a Linux datacenter IP scored a suspect_score: 8 and bot: not_detected against FingerprintJS Pro v4).We don't even lie unnecessarily. We default to host-OS matching. If you run mochi on a Linux server, it uses privacy-sensible fingerprints for Linux, not Windows, because Linux is a real-user signal. It proves that WAFs aren't actually blocking what most people think they are, which begs the question of what they are really doing in that obfuscated payload.The legitimacy argument is exactly how they captured the narrative. And nobody challenged it because the people on the other side were too busy acting like they were doing something wrong.Is this a conspiracy theory? For sure, but only because they allow it to be. Try make a conspiracy theory about the sticky riceball.

Enrichment

Theme
browser automation and scraping for AI
Vertical
Horizontal
Function
Dev tools
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
browser automation library for bun
Manually corrected
False

Could you build this?

No Creating a stealth browser automation framework that bypasses advanced anti-bot probes via relationally coherent hardware fingerprint DAGs and biomechanical movement models requires deep adversary and browser internals expertise.

What it would actually take: The project requires a raw Chrome DevTools Protocol (CDP) client implemented natively in Bun, bypassing typical Puppeteer/Playwright signatures. The core is an extensive relational DAG engine that calculates mutually consistent canvas, WebGL, WebGPU, audio, font, and device parameters, paired with mathematical human-behavior synthesis (Bezier curves, Fitts' law, lognormal digraph timing). Developing this demands deep reverse engineering of modern bot detection engines (Cloudflare Turnstile, DataDome) and continuous testing against device baselines.

Discussion

20 comments analyzed.

Competitors mentioned: Playwright, Cypress, Selenium, Camoufox, FingerprintJS Pro

Concerns raised: Website copy and documentation are incoherent and AI-generated sounding, Jargon-heavy without explaining acronyms (CDP, WAF) or technical concepts, Lacks clear, simple value proposition compared to alternatives, Basic functionality crashes or fails (navigation to certain sites, page rendering), Publishing fingerprinting mechanisms publicly defeats anti-detection purpose

Feature requests: Clear, simple messaging (e.g., performance comparisons, API compatibility), Better documentation with explained acronyms and context for non-expert users, Improved mobile and desktop responsive design for website and docs

Competitors

Other products that read as similar to this one — 127 launches clear the similarity bar, closest 8 shown.

Attention rank: #33 of 128 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 185 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a dev tools tool for Sales yet.