Obfuscated JavaScript is everywhere — malware samples, scraped webpack bundles, and "protected" third-party scripts. Reading it by hand is a nightmare: string arrays, hex escapes, _0x4a2b identifiers, dead code.
You can deobfuscate locally (Babel, de4js), but that means setting up Node, pulling dependencies, and writing your own transforms. Here's how to do it with one HTTP call instead.
What the API runs
Seven automated AST passes, in order:
- String-array decryption — obfuscator.io-style rotated arrays → plain strings
-
Constant folding —
1 + 2 * 3→7 -
Boolean reduction —
![]→false,!![]→true - Dead-code removal — unreachable branches, empty statements
-
Escape-sequence restore —
\x48\x65\x6c\x6c\x6f→"Hello" -
Numeric-literal restore —
0x12→18 -
Bracket-to-dot —
obj["prop"]→obj.prop
Every pass runs on the AST (Babel). It never evals untrusted code — string decryption runs in a sandboxed VM with hard timeouts, so malformed input returns a clean error instead of crashing.
One call
curl -X POST \
https://mega-api-mellowed-tidepool-1271.fly.dev/deobfuscate/deobfuscate \
-H 'Content-Type: application/json' \
-d '{"code":"var _0x4a2b=[\"Hello\",\"World\"];function _0x1f3a(n){return _0x4a2b[n-0];}var r=_0x1f3a(0)+\" \"+_0x1f3a(1);"}'
Response:
{
"ok": true,
"code": "var _0x4a2b = [\"Hello\", \"World\"];\nfunction _0x1f3a(n) {\n return _0x4a2b[n - 0];\n}\nvar r = _0x1f3a(0) + \" \" + _0x1f3a(1);",
"stats": { "stringArray": 0, "foldRounds": 1, "bracketToDot": 0 }
}
Use cases
- Security researchers analyzing suspicious scripts before they run
- Developers recovering lost or over-minified source
- Scraping teams decoding obfuscated webpack bundles
Free tier gets you started; higher limits and an interactive playground are on RapidAPI:
https://rapidapi.com/buigialy30206/api/javascript-deobfuscator
Top comments (0)