DEV Community

gia ly bui
gia ly bui

Posted on

How to Deobfuscate JavaScript in One API Call (No Local Tooling)

Obfuscated JavaScript is everywhere — webpack bundles, obfuscator.io output,
malware payloads. Decoding it usually means installing Babel, writing
transforms, or pasting into a web tool one file at a time.

Here's a one-call way to do it programmatically.

The API

One endpoint. Send obfuscated code, get readable source back.

curl -X POST "https://prod.api.market/api/v1/viv-data/javascript-deobfuscator/deobfuscate" \
  -H "x-api-key: YOUR_KEY" \
  -H "Content-Type: application/json" \
  -d '{"code": "var _0x4a2b=[\"log\",\"Hello\\x20World\"];(function(_0x2e8f,_0x4a2b){var _0x5a3c=function(_0x1a2b){while(--_0x1a2b){_0x2e8f[\"push\"](_0x2e8f[\"shift\"]());}};_0x5a3c(++_0x4a2b);}(_0x4a2b,0x1b3));console[_0x4a2b[0]](_0x4a2b[1]);"}'
Enter fullscreen mode Exit fullscreen mode

What comes back

{
  "ok": true,
  "code": "console.log(\"Hello World\");",
  "stats": { "passes": 7, "strings_decrypted": 2 }
}
Enter fullscreen mode Exit fullscreen mode

What it actually does (7 passes)

  • String-array decryption (obfuscator.io-style rotated arrays → plain strings)
  • Constant folding (1 + 2 * 3 → 7)
  • Boolean reduction (![] → false)
  • Dead-code removal
  • Escape-sequence restore (\x48\x69 → Hi)
  • Numeric-literal restore (0x12 → 18)
  • Bracket-to-dot (obj["prop"] → obj.prop)

Why it's safe

Every pass runs on the AST (Babel). String decryption runs in a
sandboxed VM with hard timeouts. It never evals your input — so you
can throw untrusted/malicious scripts at it without fear.

Use it from any language

const res = await fetch("https://prod.api.market/api/v1/viv-data/javascript-deobfuscator/deobfuscate", {
  method: "POST",
  headers: { "x-api-key": process.env.API_MARKET_KEY, "Content-Type": "application/json" },
  body: JSON.stringify({ code: obfuscatedCode })
});
const { code } = await res.json();
Enter fullscreen mode Exit fullscreen mode

Free tier is 100 calls/mo; Pro is $19/mo for 10k. Details:
https://api.market/store/viv-data/javascript-deobfuscator

Top comments (0)