de4js
JavaScript deobfuscator and unpacker. Runs fully offline in the browser.
Open the official app on lelinhtinh.github.io
This tool is hosted by its maintainers. Click below to open lelinhtinh.github.io in a new tab — it's their official demo.
Browse developer tools →What's next with de4js?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is de4js?
de4js is an open-source JavaScript deobfuscator and unpacker released under the MIT license that accepts heavily obfuscated or packed script inputs and produces readable, human-analyzable JavaScript source code as its output. Reverse engineers use de4js to quickly unpack suspicious scripts encountered during malware analysis, frontend developers use the utility to restore minified or obfuscated third-party library code when source maps are missing, and security auditors rely on the tool to inspect hidden payload logic inside web application bundles. de4js operates entirely within the browser environment, allowing users to unpack scripts without external server dependencies. The project code is hosted on GitHub under the MIT license with over 1600 stars, making it a recognized open-source resource for JavaScript reverse engineering. Supporting a wide variety of packers and obfuscators, de4js handles common patterns like eval-based encoding, custom string arrays, and variable renaming schemes. Analysts can inspect the source repository on GitHub to contribute new unpacker routines or review the underlying codebase.
How it works
Repository: lelinhtinh/de4js - Works offline. - Source code beautifier / syntax highlighter. - Makes obfuscated code [readable](#helper). - Performance unpackers: - **Eval**, e.g. Packer, WiseLoop - **Array**, e.g. Javascript Obfuscator, Free JS Obfuscator - [_Number](https://jsfiddle.net/ps5anL99/embedded/result,js,html,css/)
How to use it
- 1Using de4js requires pasting the target obfuscated or packed JavaScript source text directly into the main input pane provided by the application interface.
- 2Once the script text is loaded into the input buffer, the de4js engine evaluates the underlying packing structures and unpacks encoded string arrays or eval-based wrappers.
- 3Finally, users review the cleaned output displayed in the resulting syntax-highlighted editor pane and copy the formatted script for further analysis or documentation.
What it can do
- Utility
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/lelinhtinh/de4js
- license: MIT — free to use
- privacy: Opens an external demo
Limitations
- ['Extremely large script inputs can cause memory exhaustion and tab freezes; split monolithic files or use command-line alternatives.', 'Complex custom packers with encrypted runtime routines require manual dynamic instrumentation or symbolic execution alongside static analysis.']
Understanding the result
JavaScript deobfuscator and unpacker. Runs fully offline in the browser.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by de4js (MIT).
- Built with
- de4js (lelinhtinh/de4js)
- License
- MIT
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Text Input
- Output
- Processed Output
Built with lelinhtinh/de4js. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- de4js
- License
- MIT
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- lelinhtinh/de4js — GitHub Repository
Upstream project · GitHub
- MIT License
Upstream project
Frequently asked
How does de4js handle heavily obfuscated and packed JavaScript files?
de4js takes obfuscated or packed JavaScript as input and processes the source text through various unpacker routines to reveal clean, readable code. The tool evaluates common encoding patterns, such as string array rotations and eval wrappers, directly within the browser interface. Users can simply paste their target script into the input panel and immediately view the unpacked output. This eliminates the need to manually write custom regex or small parsing scripts for standard obfuscation formats. The resulting output can then be copied and utilized for further security audits or code analysis.
What licensing model governs the use and distribution of the de4js project?
The de4js project is distributed under the permissive MIT license, which grants users broad permissions to use, modify, and distribute the software. Developers can freely inspect the source code, fork the repository on GitHub, or integrate its unpacking logic into their own custom tooling workflows. This open-source licensing model encourages community contributions, resulting in over 1600 stars on its official GitHub repository. Compliance with the MIT license simply requires retaining the original copyright and license notice in derivative works or distributions.
How can developers contribute new unpacker routines to the de4js codebase?
Developers interested in adding support for new packers can access the project source repository hosted on GitHub at https://github.com/lelinhtinh/de4js. Contributions typically involve writing custom parsing logic or pattern-matching rules that identify specific obfuscation signatures. Once implemented and tested against sample payloads, contributors can submit pull requests to the main repository for review. Engaging with the project issues on GitHub also allows developers to report stubborn packing formats that require new unpacking strategies.
How does de4js compare to command-line JavaScript deobfuscation utilities?
While command-line tools like JSBeautify or AST-based Node.js scripts excel at handling massive batch processing pipelines, de4js is built for quick, interactive unpacking inside a browser environment. de4js focuses heavily on recognizing specific known packers and unpacking patterns out-of-the-box without requiring complex installation steps or environment configurations. Command-line utilities often require manual script configuration and dependency management via npm, whereas de4js provides an immediate graphical interface. However, command-line alternatives remain better suited for automated CI/CD security scanning pipelines where browser interaction is impractical.
What should I do if de4js freezes or fails to unpack a massive script file?
When processing extremely large JavaScript bundles that cause the de4js interface to freeze, analysts should first divide the file into smaller logical chunks before submission. Extremely large inputs can overwhelm the browser's parsing memory limits, resulting in unresponsiveness or out-of-memory errors. If splitting the file does not resolve the parsing failure, the target script likely utilizes a custom or heavily encrypted packer that requires specialized AST transformations. In such scenarios, developers should transition to dedicated Node.js-based AST manipulation tools or manual dynamic debugging to extract the underlying payload.