TypeNFuzz: Dynamic Type-aware Object Dependence Graph-Guided Fuzzing for JavaScript Library Bug Discovery

Yishun Zeng, Wu Yue, Chao Zhang · ACM Transactions on Software Engineering and Methodology · 2025

Node.js owes much of its popularity to an enormous library ecosystem. While this abundance speeds development, widely varying code quality complicates efforts to assure robustness. Effective library testing is hard for two reasons: (1) dynamic typing obscures the construction of valid, complex inputs and (2) crucial internal logic is hidden behind shallow exports, making deep paths difficult to reach. Existing tools handle neither challenge well. To address these challenges and elevate library quality, we propose TypeNFuzz, a novel testing approach for Node.js libraries. TypeNFuzz integrates: (1) Type-driven Input Synthesis : mines TypeScript declaration files to build semantically correct objects, defeating dynamic-typing ambiguities. (2) Deep Reachability Exploration : fuzzing guided by a dynamic and type-aware object dependence graph (ODG), systematically triggering execution deep within the internal code paths to uncover deep logic. The evaluation demonstrates the effectiveness of TypeNFuzz: it achieves 1.70–6.74 times higher code coverage than state-of-the-art tools, directly attributed to its ability to handle complex types and penetrate deep logic. Critically, it uncovered 77 defects in popular built-in and third-party libraries, significantly contributing to improved robustness and stability.

Read the paper · More papers on PaperTik