JavaScript DeObfuscator

Unpack obfuscated JavaScript into something you can actually read.

Obfuscated JavaScript on a site you are responsible for deserves a look. It might be a legitimate vendor protecting their widget — or it might be something that was injected without anyone noticing.

Deobfuscating a script

  1. Paste the obfuscated JavaScript.
  2. Run the deobfuscator to unpack and reformat it.
  3. Read the result, paying attention to any network calls.
  4. Decode any remaining string arrays manually if needed.
  5. Trace the entry points to work out what actually runs.

What to look for when auditing an unknown script

Start with the network activity. Any fetch, XMLHttpRequest, dynamically inserted <script> tag or image beacon tells you where data is going, and an unfamiliar domain is the single strongest signal something is wrong.

Then look at what it reads: document.cookie, localStorage, form field values, and anything attaching listeners to password or payment inputs. A script that reads form data and contacts an external host is a card skimmer until proven otherwise. Also check for eval and new Function, which are how a small loader turns into a large payload.

Legitimate reasons to deobfuscate

  • Security auditing of third-party scripts running on your own site.
  • Incident response after a suspected compromise.
  • Verifying that a vendor tag does only what the contract says it does.
  • Debugging a production issue in a bundle whose source map is missing.
  • Checking a browser extension before installing it.

Its limits

Deobfuscation recovers structure and behaviour, not the original source. Renamed variables stay renamed and comments are gone. Heavily flattened control flow can usually be followed but rarely reads cleanly. Expect to spend real time with it — and if you are responding to an actual incident, the code is evidence as well as a puzzle, so preserve a copy of the original before you start transforming it.

Deobfuscation questions

Can any obfuscated JavaScript be deobfuscated?

In principle yes, since the browser must ultimately be able to execute it. In practice the difficulty varies enormously. Simple packing unwinds in seconds; aggressive control flow flattening can take hours of manual work.

Will I get the original source back?

No. You get readable structure and recoverable logic. Original variable names and comments were destroyed during obfuscation and cannot be restored.

How do I tell if a script on my site is malicious?

Look at where it sends data and what it reads. Unfamiliar domains in network calls, code that reads form fields or cookies, and dynamic code execution via eval are the strongest warning signs. If you find one, treat it as an incident.

Is it legal to deobfuscate a script?

Analysing code running on infrastructure you control, or served to your own browser, is normal security practice. Redistributing someone else’s code or circumventing licensing is a separate matter governed by that code’s licence and your local law.

Is the code uploaded to your server?

Yes. Your code is sent to the server for processing, but it is not stored; see our privacy policy for details.

Cookie
We care about your data and would love to use cookies to improve your experience.