Skip to content
Aback Tools Logo

JavaScript Packer/Compressor Unpacker

Detect and unpack packed JavaScript code including the Dean Edwards Packer format. Automatically identifies the packer signature, extracts the encoded payload and keyword dictionary, and reconstructs the original readable source code. Perfect for security research, reverse engineering, and understanding compressed third-party scripts - all processing is local and private.

JavaScript Packer/Compressor Unpacker

Detect and unpack packed JavaScript code, including Dean Edwards Packer format and similar compressors. Paste packed JavaScript code to automatically identify the packer, extract the unpacking algorithm, and reveal the original readable source code. All processing runs locally in your browser - no signup required.

Packer detected: Dean Edwards Packer - ready to unpack
490 bytes
176 bytes(-314)
Packer Type
Dean Edwards
Encoding Base
62
Keywords
11
Payload Size
64% of original
Extracted Components
Encoded Payload:6 1(3,4){2 0=0;2(5 7=0;7<3.8;7++){2 9=3[7];0+=9.8*9.a}b 0}
Base
62
Word Count
11
Splitter
Split by "|"
Keyword Dictionary (11 words):
#EncodedKeyword
00function
11items
22var
33
44
55for
66
77calculateTotal
88i
99length
10aprice
Note: This unpacker handles Dean Edwards Packer format (commonly used by JavaScript compressors online). It may not work with all packer variants, custom implementations, or multi-layer packing. For heavily obfuscated code, multiple passes of unpacking may be required. Always verify the unpacked output for correctness before use.

Why Use Our JavaScript Packer/Compressor Unpacker?

Automatic Packer Detection

Instantly detects Dean Edwards Packer format and similar JavaScript compressors. The tool scans for the characteristic function(p,a,c,k,e,d) signature, identifies the encoding base, extracts keyword dictionaries, and reveals the original readable source code - all with a single click.

Complete Component Extraction

View every extracted component of the packer: the encoded payload, encoding base number, keyword count, and the full keyword dictionary with encoded-to-original mappings. The keyword table shows the base-N encoded identifier and its corresponding decoded keyword for each entry.

Copy & Download Unpacked Code

Easily export the unpacked code with Copy to Clipboard or Download as .js file buttons. Side-by-side comparison shows the packed input and unpacked output with byte-size changes so you can see exactly how much space the packing saved.

Safe & Private Browser Processing

All unpacking runs entirely in your browser using JavaScript. The packed code, extracted components, and unpacked output never leave your device. No signup, no data upload, no tracking - complete privacy for security research and malware analysis.

Common Use Cases for JavaScript Packer/Compressor Unpacker

Malware & Security Script Analysis

Security researchers and SOC analysts use the packer unpacker to analyze potentially malicious JavaScript payloads. Packed code is commonly used in drive-by downloads, phishing pages, and malware droppers. Unpacking reveals the actual malicious functionality hidden behind the compression layer.

Reverse Engineering Minified Widgets

When analyzing third-party JavaScript widgets or tracking scripts that use Dean Edwards packing, the unpacker reveals the original variable names and code structure. This helps understand what data the script collects, what APIs it calls, and how it behaves on your website.

Educational Deobfuscation Practice

Students learning JavaScript obfuscation and deobfuscation use the packer unpacker to understand how Dean Edwards packing works. The extracted components view shows exactly how the encoding base, keyword dictionary, and word-boundary replacement algorithm reconstruct the original code.

CTF Challenge Solving

Capture The Flag (CTF) participants encounter packed JavaScript in web exploitation and reverse engineering challenges. The packer unpacker quickly strips the packing layer, revealing the underlying code that contains flags, payloads, or vulnerability hints.

Legacy Code Recovery

When maintaining older web applications that used JavaScript compressors before modern minification became standard, the unpacker helps recover readable source code from packed scripts where the original unobfuscated files have been lost.

Vulnerability Research & Bug Bounty

Bug bounty hunters analyzing target applications often encounter packed JavaScript in production. Unpacking reveals the actual application logic, API endpoints, authentication flows, and potential security vulnerabilities hidden behind the compression.

Understanding JavaScript Packer/Compressor Unpacking

What Is JavaScript Packing?

JavaScript packing is a code compression technique that replaces meaningful variable names, function names, and keywords with short encoded references. The most common format is the Dean Edwards Packer, which uses a base-N encoding scheme to represent identifiers compactly. The packed output is wrapped in a self-extracting function that, when executed, reconstructs the original code by replacing encoded placeholders with the actual keywords from a dictionary. This technique was widely used in the 2000s-2010s before modern minification tools like UglifyJS and Terser became standard.

How Our Packer Unpacker Works

  1. Scan & Detect: The tool scans your JavaScript code for the characteristic Dean Edwards Packer signature - an eval() wrapping a function with parameters (p, a, c, k, e, d). This signature uniquely identifies the packer format among other compression methods.
  2. Extract Components: Using regex extraction, the tool pulls out the five key components of the packer: the encoded payload string (p), the encoding base number (a, typically 62), the keyword count (c), the packed keyword list (k), and the splitter character used to separate keywords. These components are displayed in the extracted components section.
  3. Reconstruct Original Code: The unpacker implements the Dean Edwards decoding algorithm: it converts each numeric index to its base-N encoded form using digits 0-9 and letters a-z, then replaces every word-boundary occurrence of the encoded form in the payload with the corresponding keyword from the dictionary. The result is the original readable JavaScript source code.

What Gets Unpacked

  • Keyword References: Numeric placeholders in the packed payload (represented as short encoded strings like 0, 1, a, b, etc.) are replaced with the actual JavaScript keywords and identifiers from the dictionary array.
  • Variable & Function Names: Meaningful names that were replaced with encoded references during packing are restored to their original form, revealing the actual purpose of each variable and function.
  • String Literals: String values that were extracted and stored in the keyword dictionary are placed back into the code at their original positions, making the code readable again.
  • Code Structure: The overall code structure (loops, conditionals, function calls, object access patterns) is fully preserved during unpacking. Only the encoded identifiers are transformed back to their original form.

Privacy & Limitations

Our JavaScript Packer/Compressor Unpacker processes everything locally in your browser. Your packed code, extracted components, and unpacked output never leave your device - no uploads, no server processing, no data storage. However, this tool specifically handles the Dean Edwards Packer format and structurally similar compressors. It may not work with custom packer implementations, multi-layer packed code, or modern obfuscation tools like Jscrambler or Obfuscator.io. For multi-layer packed code, you may need to run the unpacker multiple times, passing the output of each pass back as input until no more packer signatures are detected. Always verify unpacked code for correctness before relying on it.

Frequently Asked Questions About JavaScript Packer/Compressor Unpacker

A JavaScript packer/compressor unpacker is a tool that reverses code compression techniques like the Dean Edwards Packer. It detects packed code by its characteristic signature, extracts the encoded components, and reconstructs the original readable source code by replacing encoded placeholders with the actual keywords from the packing dictionary.

The Dean Edwards Packer is a popular JavaScript compression format that wraps code in a self-extracting function with the signature function(p,a,c,k,e,d). The parameters represent: p (the encoded payload with placeholders), a (the encoding base, usually 62), c (the number of keyword entries), k (the comma-separated keyword list), e (the encoding function), and d (an optional dictionary object). The format was widely used from the mid-2000s through the 2010s.

Our unpacker handles the standard Dean Edwards Packer format and structurally similar compressors. It may not work with custom packer implementations, multi-layer packed code (where the unpacked output is itself packed again), or modern obfuscation tools that use entirely different techniques like control flow flattening or AST transformation.

The keyword dictionary maps numeric indices to actual JavaScript keywords and identifiers. In the unpacking process, each index is encoded to a base-N string (using digits 0-9 and letters a-z) and then every occurrence of that encoded string as a whole word in the payload is replaced with the corresponding keyword from the dictionary. The extracted components view shows the complete mapping table.

Absolutely. All unpacking happens entirely in your browser using JavaScript. Your packed code, the extracted components, and the unpacked output never leave your device. No data is uploaded to any server. No signup required, no tracking, complete privacy.

For multi-layer packed code (where the unpacked output is itself still packed), you may need to run the unpacker multiple times. Paste the unpacked output back into the input panel and click Unpack again. Each pass removes one layer of packing until the code is fully readable.

The encoding base (typically 62) determines how keyword indices are converted to string identifiers. Base 62 uses digits 0-9 and letters a-z and A-Z, producing short identifiers like "0", "1", "a", "b", "Z", etc. A higher base produces shorter encoded identifiers, resulting in more compact packed output.

Yes - our JavaScript Packer/Compressor Unpacker is 100% free with no signup required, no premium tier, no usage limits, no file size restrictions, and no advertisements. Use it unlimited times for security research, education, or any other purpose.