Obfuscated JavaScript is everywhere — webpack bundles, obfuscator.io output,
malware payloads. Decoding it usually means installing Babel, writing
transforms, or pasting into a web tool one file at a time.
Here's a one-call way to do it programmatically.
The API
One endpoint. Send obfuscated code, get readable source back.
curl -X POST "https://prod.api.market/api/v1/viv-data/javascript-deobfuscator/deobfuscate" \
-H "x-api-key: YOUR_KEY" \
-H "Content-Type: application/json" \
-d '{"code": "var _0x4a2b=[\"log\",\"Hello\\x20World\"];(function(_0x2e8f,_0x4a2b){var _0x5a3c=function(_0x1a2b){while(--_0x1a2b){_0x2e8f[\"push\"](_0x2e8f[\"shift\"]());}};_0x5a3c(++_0x4a2b);}(_0x4a2b,0x1b3));console[_0x4a2b[0]](_0x4a2b[1]);"}'
What comes back
{
"ok": true,
"code": "console.log(\"Hello World\");",
"stats": { "passes": 7, "strings_decrypted": 2 }
}
What it actually does (7 passes)
- String-array decryption (obfuscator.io-style rotated arrays → plain strings)
- Constant folding (
1 + 2 * 3→7) - Boolean reduction (
![]→false) - Dead-code removal
- Escape-sequence restore (
\x48\x69→Hi) - Numeric-literal restore (
0x12→18) - Bracket-to-dot (
obj["prop"]→obj.prop)
Why it's safe
Every pass runs on the AST (Babel). String decryption runs in a
sandboxed VM with hard timeouts. It never evals your input — so you
can throw untrusted/malicious scripts at it without fear.
Use it from any language
const res = await fetch("https://prod.api.market/api/v1/viv-data/javascript-deobfuscator/deobfuscate", {
method: "POST",
headers: { "x-api-key": process.env.API_MARKET_KEY, "Content-Type": "application/json" },
body: JSON.stringify({ code: obfuscatedCode })
});
const { code } = await res.json();
Free tier is 100 calls/mo; Pro is $19/mo for 10k. Details:
https://api.market/store/viv-data/javascript-deobfuscator
Top comments (0)