How Wand-Enhancer Patches the WeMod Electron Application: A Technical Deep Dive

Wand-Enhancer performs a local offline patching process that extracts the WeMod (Wand) Electron ASAR archive, injects JavaScript modifications via regex-based replacements, rebuilds the archive with AsarCreator, and patches the version.dll binary to disable ASAR integrity checks.

Wand-Enhancer is an open-source .NET utility that modifies the WeMod (referred to as "Wand") Electron application through purely local file manipulation. By targeting the resources/app.asar archive and accompanying binaries, this patcher enables pro features, developer tools, and optional remote control capabilities without requiring network-based exploits or external servers.

The Three-Stage Patching Pipeline

The core patching logic resides in WandEnhancer/Core/Enhancer.cs and follows a deterministic three-stage workflow that transforms the original WeMod installation into a patched state.

Stage 1: ASAR Extraction with AsarExtractor

The process begins with the AsarExtractor class defined in AsarSharp/AsarExtractor.cs. The patcher locates the target WeMod installation directory and identifies the resources/app.asar file. Using AsarExtractor.ExtractAll(), it decompresses the entire ASAR archive into a temporary working directory (_unpackedPath).

This extraction creates a writable copy of the Electron application's file tree, including all JavaScript bundles, HTML files, and Node modules. The extraction preserves the original directory structure, ensuring that relative imports and require statements remain functional during the subsequent modification phase.

Stage 2: JavaScript Injection via PatchEntry Definitions

Once extracted, the engine applies JavaScript patches defined in WandEnhancer/Core/EnhancerConfig.cs. This file contains a static dictionary mapping each EPatchType enum value—such as ActivatePro, DevToolsOnF12, and RemoteWebPanelPreview—to one or more PatchEntry objects.

Each PatchEntry contains:

  • Search hints: Regex patterns or literal strings used to locate target code blocks
  • Patch content: Either a literal JavaScript snippet or a factory function generating the replacement code
  • Replacement logic: The Enhancer.ApplyJsPatch method searches extracted files for these hints and performs surgical replacements

For example, the RemoteWebPanelPreview patch injects a bridge loader that executes when the app becomes ready:

new PatchEntry {
    Patch = "${app}.whenReady().then(()=>{"
          + "try{const p=require(\"node:path\");"
          + "require(p.join(__dirname,\"remote-panel\",\"bridge.cjs\")).installWandRuntime(require(\"electron\"));}"
          + "catch(e){}"
          + "return run()})"
}

The engine iterates through all unpacked files, applying each selected patch from the PatchConfig object passed during initialization.

Stage 3: Archive Reconstruction and Binary Patching

After successful JavaScript modification, AsarCreator (from AsarSharp/AsarCreator.cs) rebuilds the final app.asar file with the patched contents. Simultaneously, the patcher modifies the version.dll proxy DLL—specifically patching the ASAR integrity verification fuse byte—to allow the modified archive to load without triggering Electron's built-in integrity checks.

Additional binary patches target specific reducer functions and account language settings through regex replacements on bundled JavaScript chunks, ensuring the application initializes with the modified state.

Remote Web Panel Implementation

When users select the RemoteWebPanelPreview option in the patch configuration, Wand-Enhancer integrates a TypeScript-based bridge system that exposes WeMod's internals via a local network interface.

Bridge Injection and Runtime Installation

The patcher copies the compiled bridge file web-panel/dist/bridge.cjs into a newly created remote-panel/ directory inside the reconstructed ASAR. The JavaScript patch injected during Stage 2 invokes installWandRuntime(require("electron")) immediately after the app initializes, spawning a LAN HTTP and WebSocket server on port 3223.

This bridge implementation, defined in web-panel/bridge/src/protocol-router.ts, establishes an IPC/WSS protocol layer that intercepts Electron events and exposes them through a runtime API (wand-remote-bridge). The system synchronizes game state, trainer status, and UI actions between the Electron renderer and external clients.

IPC Protocol and Local Server Architecture

The bridge operates entirely within the patched Electron context, requiring no external network calls during the patching process itself. Once injected, it creates a localhost-only server that accepts connections from authorized clients on the same network, enabling remote control of the WeMod interface through standardized message protocols while maintaining the patched application's offline-first architecture.

User Interface and Patch Orchestration

User interaction flows through WandEnhancer/View/Popups/PatchVectorsPopup.xaml.cs. When a user clicks the Patch button in MainWindowVm, the application instantiates a PatchVectorsPopup presenting checkboxes corresponding to available EPatchType values.

The selected patches populate a PatchConfig instance passed to new Enhancer(WeModInfo, Log, config).Patch(). This orchestrator method coordinates the extraction, modification, and repacking sequence, providing real-time feedback through the logging interface while disabling UI controls during the operation to prevent concurrent modification attempts.

Safety Mechanisms and Error Handling

The patching engine implements multiple safeguards to prevent corruption of the WeMod installation. The Enhancer.CouldFileContainRemainingPatch method pre-filters candidate files before expensive regex operations, while PatchAsar (lines 122-176 in Enhancer.cs) maintains a validation ledger.

If any requested patch cannot be applied—typically due to version mismatches or missing search hints—the engine throws a detailed exception listing the remaining unapplied EPatchTypes. This atomic failure mechanism ensures users never operate partially patched builds that might exhibit undefined behavior or stability issues.

Additionally, the patcher validates file handles and directory permissions before extraction, and the ASAR reconstruction process verifies checksums to ensure the output archive maintains structural integrity compatible with Electron's loader.

Summary

  • ASAR manipulation: Wand-Enhancer uses AsarExtractor and AsarCreator to decompress, modify, and repack the Electron archive while preserving import structures.
  • Regex-driven patches: JavaScript modifications are defined in EnhancerConfig.cs as PatchEntry objects containing search hints and replacement snippets for specific EPatchType targets.
  • Binary patching: The tool modifies version.dll to disable ASAR integrity checks, allowing the patched archive to load without cryptographic verification failures.
  • Remote capabilities: Optional RemoteWebPanelPreview injection adds a TypeScript bridge (bridge.cjs) that exposes a localhost server on port 3223 for external control.
  • Atomic operations: The patching process validates all modifications before finalizing, throwing descriptive errors if any component fails to ensure installation safety.

Frequently Asked Questions

What specific files does Wand-Enhancer modify in the WeMod installation?

Wand-Enhancer primarily targets three components: the resources/app.asar archive containing the Electron application code, the version.dll binary responsible for ASAR integrity verification, and specific JavaScript bundle files within the ASAR such as those containing setAccountLanguage and setAccountReducer functions. The patcher creates temporary working directories during operation but only modifies files within the official WeMod installation path.

Is the patching process reversible or does it affect automatic updates?

The patching process modifies local files directly, and while the tool creates backups of the original ASAR during extraction, reverting requires manual restoration or reinstallation of WeMod. Automatic updates from the official WeMod servers will overwrite patched files, requiring users to rerun Wand-Enhancer after each client update to maintain modifications, as the update mechanism replaces the modified app.asar and version.dll with official versions.

How does the remote web panel communicate with the Electron app?

The remote web panel utilizes an injected TypeScript bridge (web-panel/dist/bridge.cjs) that installs itself into the Electron main process via installWandRuntime. This bridge establishes an IPC (Inter-Process Communication) protocol router and opens a WebSocket server on port 3223, allowing the renderer process to expose internal game state and trainer controls through a localhost HTTP interface accessible to browsers or dedicated clients on the same network.

What happens if a patch fails to apply to a specific Wand version?

If the Enhancer.PatchAsar method encounters a version mismatch where search hints fail to locate target patterns, it immediately aborts the entire operation and raises an exception detailing which EPatchType values could not be applied. This atomic failure mechanism prevents partial modifications that could corrupt the installation, requiring users to wait for an updated patch definition in EnhancerConfig.cs compatible with their specific WeMod version.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →