Note
This repository contains the source code and process explanation for building the SpiderCat jailbreak book. If you're looking for instructions on how to actually perform the jailbreak, go to KindleModding!
build.py builds spidercat.azw3, a fixed-layout Kindle book that, when opened, runs a shell command (by default, executing jb.sh Kindle jailbreak) via a JSArray::sort use-after-free in webreader's WebKit.
Supported firmware: Kindle OS 5.16.3 through 5.19.5 (hard-float builds). 5.19.6 and later patched the entry point by sandboxing the webreader iframe.
- Python3 (runs the build)
azwjs.py(MOBI/AZW3 container library)kindlegenonPATH(Amazon's KF8 compiler; see below)
kindlegen is Amazon's proprietary KF8 compiler. It is not open source; it was historically a standalone download and is now bundled inside Kindle Previewer (macOS/Windows, free from Amazon). Point kindlegen on your PATH at that binary, e.g.:
# macOS / Windows (Kindle Previewer install)
ln -s "/Applications/Kindle Previewer 3.app/Contents/MacOS/lib/fc/bin/kindlegen" ~/.local/bin/kindlegenOn Linux, Amazon provides no current Kindle Previewer build. Options:
-
Use the legacy standalone Linux
kindlegen(a 32-bit x86 binary; Amazon no longer distributes it officially). On 64-bit Linux you must install 32-bit compatibility libraries first, at minimum the 32-bit C library:- Debian/Ubuntu:
sudo dpkg --add-architecture i386 && sudo apt update && sudo apt install libc6:i386 - Fedora:
sudo dnf install glibc.i686 - Arch:
enable [multilib], then sudo pacman -S lib32-glibc
If running it says "No such file or directory" even though the file exists, the 32-bit libraries are missing.
ldd ./kindlegenshows which ones. - Debian/Ubuntu:
-
Or run Kindle Previewer's kindlegen inside a Windows or macOS VM.
Verify with:
kindlegen -locale en 2>&1 | head -1 # should print kindlegen + a version- Pillow (resizes the cover/thumbnail)
kindlegen's output thumbnail is a small, low-resolution GIF that looks pretty bad even in e-ink. Thumbnail seems to only appear in firmwares 5.19.x. Automatically installed if you use uv, or:
pip install pillowoffsets.json: per-firmware constants (entry-point fingerprint, libc offsets)page.xhtml: the visible page shown while the exploit runsstyle.css: its stylesheetcover.png: optional library thumbnail (shows on 5.19.x only?)
python3 build.pyThis produces spidercat.azw3.
Derive the per-firmware constants from three binaries pulled from a firmware rootfs (either from a device or from an OTA update package):
lib/libc.so.6usr/lib/libwebkitgtk-1.0.so.0usr/bin/webreader
Run derive_offsets.py (in this directory; needs nm + readelf from binutils on PATH):
python3 derive_offsets.py --json libc.so.6 libwebkitgtk-1.0.so.0 webreaderbuild.py only consumes four of the emitted fields, e_entry, system, g_strcmp0_got, candidates, and they must be stored as 0x… hex strings. Add them to offsets.json under a "Model-version" key (matching the shape of the existing entries) and rebuild:
python3 build.py