Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
hermes-decomp — A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into readable JavaScript. | Kitploit
Tools/GitHubGitHub/symbioticsec/hermes-decomp
Android SecurityStatic AnalysisiOS SecurityCode AnalysisDynamic Code Analysis (DAST)Reverse EngineeringDebuggersMobile SecurityBinary AnalysisLearning & EducationAI-Assisted Reversing
138124 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
symbioticsec/hermes-decomp

hermes-decomp

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into readable JavaScript.

View Repository

Hermes Bytecode Decompiler

Build

Rust decompiler for Hermes bytecode (.hbc), the JS engine behind React Native. Supports HBC 40 to 99.

Install

Pre-built binaries (Linux / macOS / Windows) from Releases or Actions:

Asset suffixPlatform
linux-x86_64 / linux-arm64Linux
macos-arm64 / macos-x86_64macOS
windows-x86_64Windows

Archives include hermes-decomp and hermes-mcp. Verify: shasum -a 256 -c SHA256SUMS.

root@kitploit:~
hermes-decomp update --check      # or --install / --version v0.1.7

From source (Rust 1.70+):

root@kitploit:~
git clone https://github.com/SymbioticSec/hermes-decomp.git
cd hermes-decomp && cargo build --release
# → target/release/hermes-decomp  target/release/hermes-mcp

Quick start

root@kitploit:~
hermes-decomp info app.hbc
hermes-decomp disasm app.hbc --function 5 --info --show-offsets
hermes-decomp decompile app.hbc -o out.js          # progress on stderr
hermes-decomp decompile app.hbc --function 42
hermes-decomp tui app.hbc
hermes-decomp xref app.hbc --query "loginWithToken"

Disassembly Example

Decompilation Example

What it does

Full flags and examples → docs/USAGE.md.

Notes:

  • Full-bundle decompile uses an on-disk .hdcache for fast reloads. Pass --no-cache to force.
  • Write tools patch bytecode / HASM. They do not recompile decompiled JavaScript.
  • decompile -o … prints pipeline stages on stderr.

MCP & library

  • MCP server (hermes-mcp) for AI assistants → docs/MCP.md
    Config template: mcp-config.example.json
  • Rust crate hbc-decomp → docs/LIBRARY.md
root@kitploit:~
cargo build --release -p hbc-decomp-mcp

Contributing

See CONTRIBUTING.md. Please open an issue before a PR.

root@kitploit:~
cargo build --release --workspace && cargo test --workspace

Resources

  • Hermes Engine · React Native

License

MIT. See LICENSE.

Download Tool
AreaCommands (highlights)
Readinfo, disasm, decompile, tui, extract, modules, deps
Analyzexref, callgraph, graphviz, closures, debug, dump, bin-diff
RE helperssecrets, frida-hooks
Write (bytecode only)emit-hasm, asm, asm-check, patch-string, patch-function, inject-stub, create