Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/ejfkdev/jd
Static AnalysisDynamic Analysis (Sandboxing)Code AnalysisReverse EngineeringMalware AnalysisUtilities & Frameworks
GitHubejfkdev/jd

jd

Go CLI that deobfuscates javascript-obfuscator (obfuscator.io) output and unminifies JavaScript using AST transforms, static decoding, and a goja sandbox fallback.

View Repository
2181 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

jd

CI Release License Go Version Release zread

中文

jd is a Go tool that deobfuscates javascript-obfuscator (obfuscator.io) output and unminifies JavaScript. It is a Go port of webcrack and synchrony.

Features

Obfuscator.io Deobfuscation

Detects and reverses javascript-obfuscator output:

  • String array detection (function-wrapped and simple array forms, var/const/let)
  • Array rotator detection (push/shift IIFE with break condition)
  • Decoder detection (index-shift, Base64/RC4/custom encodings, two-parameter decoders)
  • Wrapper alias resolution (var/function aliases to decoders)
  • Hybrid decoding — static simulation (SIMPLE/Base64/RC4) with goja sandbox fallback for custom encoders
  • Helper removal — string array, rotator, and decoder declarations removed after decoding

Unminify

20+ readability transforms:

TransformExample
computed-propertiesconsole["log"] → console.log
merge-strings"a" + "b" → "ab"
unminify-booleans!0 → true, !1 → false
number-expressions1 + 2 → 3
void-to-undefinedvoid 0 → undefined
raw-literals0x1 → 1
sequencea(), b(), c() → separate statements
split-variable-declarationsvar a=1, b=2 → var a=1; var b=2
block-statementswrap single-statement bodies in { }
logical-to-ifa && b() → if (a) b()
ternary-to-ifa ? b() : c() → if (a) b() else c()
merge-else-ifelse { if (...) } → else if (...)
for-to-whilefor(;;) → while(true)
yoda5 === x → x === 5
infinity1/0 → Infinity
invert-boolean-logic!(a == b) → a != b
unary-expressionsdrop no-op void/!/typeof at statement level
remove-double-not!!true → true

ES Module Support

goja's parser does not support ES module syntax (import/export). jd pre-extracts import/export statements, parses the remaining script, runs transforms, then prepends the statements to the output. Dynamic import() expressions are correctly distinguished from import declarations.

Regex-Safe Formatting

For files goja cannot fully parse (e.g. Monaco editor language definitions with heavy regex usage), jd falls back to source-level formatting: a tokenizer splits on semicolons while preserving regex literals, strings, and comments verbatim.

Installation

macOS (Homebrew)

brew install ejfkdev/tap/jd

Pre-built binaries

Download from GitHub Releases (Linux/macOS/Windows, x86_64/ARM64).

Build from source

go build -o jd .

Usage

# Deobfuscate a file (output to stdout)
jd obfuscated.js

# Write to a file
jd obfuscated.js -o cleaned.js

# Read from stdin
cat obfuscated.js | jd -

# Process a directory — recursively processes all .js/.mjs/.cjs files,
# mirrors the directory tree to the output directory.
jd src/ -o dist/

# Directory mode with default output: creates <input>-deobfuscated
jd src/

# Specify file extensions
jd src/ -o dist/ --ext .js,.mjs

# Parallel processing (N workers, default: number of CPUs)
jd src/ -o dist/ -j 8

# Skip non-code files (only output processed JS)
jd src/ -o dist/ --copy-noncode=false

# Only deobfuscate, skip unminify
jd --unminify=false obfuscated.js

# JSON output with warnings
jd --json obfuscated.js

Flags

FlagDefaultDescription
-o, --outputstdoutoutput file or directory (default for dir: <input>-deobfuscated)
--deobfuscatetruerun obfuscator.io deobfuscation
--unminifytruerun readability transforms
--sandboxautodecoder execution: auto (static then sandbox), only (always sandbox), off (only static)
--timeout10sper-file sandbox timeout
--ext.js,.mjs,.cjsfile extensions to process in directory mode
-j, --workers0 (=CPU)parallel workers for directory mode
--copy-noncodetruecopy non-code files to output directory
-v, --verbosefalseprint diagnostics to stderr
--jsonfalseemit {code, warnings} JSON

Architecture

jd/
├── main.go                     # CLI entry
├── internal/
│   ├── cli/                    # cobra CLI (i18n: English/Chinese)
│   ├── deobfuscator/           # top-level pipeline + ES module preprocessing
│   ├── jsast/                  # AST walker (Cursor, Replace, Remove, Clone)
│   ├── codegen/                # AST → JavaScript printer (pretty/compact)
│   ├── scope/                  # lexical scope & binding analysis
│   ├── sandbox/                # goja VM wrapper for decoder execution
│   ├── decoder/                # static decoding: Base64/RC4/rotation
│   ├── deobfuscate/            # string-array/rotator/decoder detection + transforms
│   ├── unminify/               # 20 readability transforms + fixpoint runner
│   └── transform/              # Transform abstraction + ApplyFixpoint
└── testdata/samples/           # test fixtures

Pipeline

parse → splitModuleStatements → deobfuscate → unminify → generate
  1. Parse — goja parser with IgnoreRegExpErrors; falls back to source-level formatting for unparseable files
  2. Deobfuscate — detect obfuscator.io string array/rotator/decoders, decode all call sites (static first, sandbox fallback), remove helpers
  3. Unminify — fixpoint loop (≤20 passes) of merged readability transforms
  4. Generate — pretty-mode codegen with operator precedence and correct parenthesisation

Hybrid Decoding

The decoder uses a two-stage approach:

Download Tool