Static JavaScript deobfuscation and malware triage. The analysed code is never executed.
Unpacks obfuscator.io string arrays, Dean Edwards P.A.C.K.E.R., encoded strings and inline source maps by parsing and rewriting source, so it is safe to point at live skimmers and loaders.
| 🌐 Web app and API | defuscator.com · free demo |
| ⌨️ CLI | npx defuscator suspicious.js · defuscator-cli |
| ✅ GitHub Action | SARIF to code scanning, PR annotations · defuscator-action |
| 🧩 VS Code | Deobfuscate in the editor · defuscator-vscode |
| 📊 Benchmark | Scored against the real obfuscators, verified by execution · deobfuscation-benchmark |
| 📚 Curated list | awesome-javascript-deobfuscation |
Found a sample we get wrong? Open an issue.