
Un potente decompilatore che consente di eseguire il reverse engineering di app mobili React Native convertendo i loro file bytecode Hermes compilati (.hbc) nuovamente in JavaScript leggibile.

Decompilatore Rust per il bytecode Hermes (.hbc), il motore JS alla base di React Native. Supporta HBC dalla 40 alla 99.
Binari precompilati (Linux / macOS / Windows) disponibili su Releases o Actions:
| Suffisso asset | Piattaforma |
|---|---|
linux-x86_64 / linux-arm64 | Linux |
macos-arm64 / macos-x86_64 | macOS |
windows-x86_64 | Windows |
Gli archivi includono hermes-decomp e hermes-mcp. Verifica: shasum -a 256 -c SHA256SUMS.
hermes-decomp update --check # or --install / --version v0.1.7
Dai sorgenti (Rust 1.70+):
git clone https://github.com/SymbioticSec/hermes-decomp.git
cd hermes-decomp && cargo build --release
# → target/release/hermes-decomp target/release/hermes-mcp
hermes-decomp info app.hbc
hermes-decomp disasm app.hbc --function 5 --info --show-offsets
hermes-decomp decompile app.hbc -o out.js # progress on stderr
hermes-decomp decompile app.hbc --deep -o out.js # recover more names, slower
hermes-decomp decompile app.hbc --function 42
hermes-decomp tui app.hbc
hermes-decomp xref app.hbc --query "loginWithToken"


| Area | Comandi (in evidenza) |
|---|---|
| Lettura | info, disasm, decompile, tui, extract, modules, deps |
| Analisi | xref, callgraph, graphviz, closures, debug, dump, bin-diff |
| Strumenti RE | secrets, frida-hooks |
| Scrittura (solo bytecode) | emit-hasm, asm, asm-check, patch-string, patch-function, inject-stub, create |
Flag completi ed esempi → docs/USAGE.md.
Note:
decompile sull'intero bundle utilizza una .hdcache su disco per ricaricamenti rapidi. Usa --no-cache per forzare.decompile -o … stampa le fasi della pipeline su stderr.hermes-mcp) per assistenti AI → docs/MCP.mdmcp-config.example.jsonhbc-decomp → docs/LIBRARY.mdcargo build --release -p hbc-decomp-mcp
Vedi CONTRIBUTING.md. Apri una issue prima di una PR.
cargo build --release --workspace && cargo test --workspace
MIT. Vedi LICENSE.