JavaScript String Unpacker
Extract and decode hidden strings from obfuscated JavaScript code. Automatically detects hex-encoded strings, Unicode escape sequences, Base64 payloads, split/concatenated strings, XOR-encrypted strings, and String.fromCharCode() constructions. Includes an interactive mapping table showing every encoded string alongside its decoded value. Free, private, and no signup required.
Extract and decode hidden strings from obfuscated JavaScript code. Automatically detects hex-encoded strings, Unicode escape sequences, Base64 payloads, split/concatenated strings, XOR-encrypted strings, and String.fromCharCode() constructions. Includes an interactive mapping table showing every encoded string alongside its decoded value.
Paste obfuscated JavaScript code above and click Unpack Strings to automatically extract and decode hidden strings. Click Load example obfuscated codeto try it with sample obfuscated JavaScript containing various string encoding techniques.
Why Use Our JavaScript String Unpacker?
Instant String Extraction & Decoding
Unpack hidden strings from obfuscated JavaScript instantly. Our string unpacker automatically detects hex-encoded strings (\xXX), Unicode escape sequences (\uXXXX), Base64-encoded payloads, split strings joined with +, XOR-encrypted strings, and String.fromCharCode() constructions. Each encoded string is decoded and displayed with its original and unpacked value side by side.
Secure & Private Code Processing
All JavaScript string unpacking happens entirely in your browser. Your obfuscated code, decoded strings, and extraction results never leave your device. No data uploaded, no tracking, no signup required - complete privacy for all your code analysis work.
Online String Unpacker - No Installation
Use the JavaScript string unpacker directly in any modern browser with no downloads, apps, or plugins required. Features a two-panel editor, auto-detection of multiple encoding methods, and an interactive mapping table showing every encoded-to-decoded string transformation.
Multi-Encoding Detection with Mapping Table
Our string unpacker detects and decodes: hex-encoded strings (\xXX), Unicode escape sequences (\uXXXX), Base64-encoded payloads, split/concatenated strings joined with +, XOR-encrypted character codes, and String.fromCharCode() constructions. Each detected encoding is clearly listed with count, description, and example matches from your code.
Common Use Cases for JavaScript String Unpacker
Extracting Hidden Strings from Obfuscated JavaScript
Security researchers use the JavaScript string unpacker to extract and decode hidden strings from obfuscated scripts. Paste obfuscated code to instantly reveal encoded API endpoints, configuration values, error messages, and other strings hidden behind hex escapes, Unicode sequences, and Base64 encoding.
Malware Analysis & Threat Intelligence
Cybersecurity professionals analyze malicious scripts by extracting obfuscated strings that often contain command-and-control URLs, payload delivery endpoints, encryption keys, and data exfiltration targets. The string unpacker decodes each obfuscated string and lists them in an easy-to-review mapping table.
Reverse Engineering Third-Party Scripts
Developers reverse-engineer obfuscated third-party JavaScript bundles to understand what data they collect and send. The string unpacker reveals encoded tracking URLs, analytics endpoints, and data collection field names that would otherwise be invisible during code review.
Debugging Obfuscated Production Code
Frontend developers debug minified and obfuscated production JavaScript by using the string unpacker to decode error messages, log statements, and configuration values that have been hidden behind string encoding, making debugging sessions much more productive.
Vulnerability Research & Security Audits
Security auditors use the JavaScript string unpacker during code audits to extract hidden strings from obfuscated JavaScript components. The decoding mapping table provides a clear picture of what data is being processed, transmitted, and stored by the analyzed code.
Learning About JavaScript String Obfuscation
Students and developers learning about code obfuscation use the string unpacker to understand how different string encoding techniques work. The interactive mapping table shows exactly how each encoded string transforms to its decoded form, making it a valuable educational tool.
Understanding JavaScript String Unpacking
What is JavaScript String Unpacking?
JavaScript string unpacking is the process of extracting and decoding hidden or encoded strings from obfuscated JavaScript code. Obfuscators commonly use various string encoding techniques - hex escape sequences, Unicode escapes, Base64 encoding, split concatenation, XOR ciphers, and String.fromCharCode() constructions - to hide meaningful strings like URLs, API endpoints, error messages, configuration values, and encryption keys from casual inspection and automated analysis.
Our JavaScript string unpacker automatically detects these encoding techniques, extracts every encoded string, and displays them alongside their decoded values in an interactive mapping table. The tool also provides a side-by-side view of the original obfuscated code and the unpacked version where all strings have been restored to their readable form. All processing runs locally in your browser with no data sent to any server.
How Our JavaScript String Unpacker Works
- 1. Paste Obfuscated JavaScript: Paste your obfuscated JavaScript code into the input panel, or click the example button to load sample obfuscated code with various string encoding techniques. The string unpacker scans the code for six common encoding methods: hex-encoded strings, Unicode escape sequences, Base64-encoded strings, split/concatenated strings, XOR-encrypted strings, and String.fromCharCode() constructions.
- 2. Click Unpack Strings: The tool analyzes every string literal in your code. Hex escape sequences like
\\x48\\x65\\x6c\\x6c\\x6fare decoded to readable text (Hello). Unicode escapes like\\u0048\\u0065are resolved to their characters. Base64 strings are decoded to reveal hidden payloads. Split strings like"Hel" + "lo"are merged back into single strings. - 3. Review Mapping Table & Export: The unpacked strings appear in a detailed mapping table showing each original encoded string and its decoded value. The code output panel shows the full code with all strings unpacked to their readable form. Copy the unpacked code to your clipboard or download it as a .js file. The mapping table can be expanded or collapsed for easier navigation.
What String Encoding Techniques Can Be Detected
- Hex-Encoded Strings: Strings where each character is represented as a hex escape sequence like
\\x48\\x65\\x6c\\x6c\\x6f(decoded: "Hello"). These are decoded back to their original characters, revealing hidden text, URLs, and configuration values stored as hex byte sequences. - Unicode Escape Sequences: Characters hidden behind
\\uXXXXsequences (four hex digits per character) are decoded to readable Unicode characters. Commonly used to hide property names and string literals from simple text search. - Base64 Encoded Strings: Long alphanumeric strings with padding (
=or==) that match Base64 patterns are decoded using browser-native atob(). Frequently used to encode binary data and long strings. - Split/Concatenated Strings: Strings split into multiple fragments and joined with
+to avoid revealing the full string in static analysis (e.g.,"Hel" + "lo" + " Wo" + "rld"). - XOR-Encrypted Strings & String.fromCharCode(): Strings constructed by XOR-ing character codes with a key byte, and strings built using
String.fromCharCode()with arrays of character codes. Both techniques are detected and decoded to reveal the original text.
Privacy, Security & Availability
The JavaScript string unpacker is 100% free with no signup required. All string extraction and decoding is performedlocally in your browser using JavaScript pattern matching - your obfuscated code, decoded strings, and analysis resultsnever leave your device. There areno file size limits or usage caps. The tool detects six common string encoding techniques, provides a detailed mapping table of encoded-to-decoded values, and includes copy-to-clipboard and download functionality. Use it as many times as you need to unpack obfuscated JavaScript strings.
Frequently Asked Questions About JavaScript String Unpacker
A JavaScript string unpacker is a tool that extracts and decodes hidden or encoded strings from obfuscated JavaScript code. It detects common string encoding techniques like hex escape sequences, Unicode escapes, Base64 encoding, split concatenation, XOR encryption, and String.fromCharCode() constructions, then decodes each one to reveal the original readable string.
The JavaScript string unpacker detects six techniques: hex-encoded strings (\xXX escapes), Unicode escape sequences (\uXXXX), Base64-encoded strings, split/concatenated strings joined with +, XOR-encrypted strings (charCodeAt + ^), and String.fromCharCode() constructions. Each detected technique is listed with its count and decoded value.
Hex-encoded strings use the pattern \x followed by two hexadecimal digits per character. For example, \x48\x65\x6c\x6c\x6f represents "Hello". The unpacker scans for this pattern, extracts each hex pair, converts it to its character equivalent using String.fromCharCode(), and reassembles the full readable string. The decoded value is shown alongside the original encoded string in the mapping table.
This tool handles the six most common string encoding techniques used in JavaScript obfuscation. Advanced techniques like runtime string decryption, WebAssembly-based string loading, or dynamically fetched strings may require additional analysis tools. The tool reports which techniques were detected and how many encoded strings were found, helping you understand the complexity of the obfuscation used.
Absolutely. The JavaScript string unpacker runs entirely in your browser. Your obfuscated code, decoded strings, and analysis results are never sent to any server, stored in a database, or tracked in any way. All processing happens locally on your device - nothing leaves your computer. No signup required.
String.fromCharCode() obfuscation builds strings from arrays of character codes, for example: String.fromCharCode(72, 101, 108, 108, 111) produces "Hello". The unpacker detects these calls, extracts the numeric arguments, and converts each code to its character using the same fromCharCode() method, then displays the decoded string.
Yes. The string unpacker provides a detailed mapping table that lists every encoded string found in your code alongside its decoded value. The table includes the detection method (hex, Unicode, Base64, etc.), the original encoded form, and the decoded result. You can expand the table to see all entries or collapse it for a compact view.
Yes. Security researchers, penetration testers, and malware analysts use the JavaScript string unpacker to extract hidden strings from potentially malicious scripts. The decoded strings often reveal critical information like command-and-control URLs, API endpoints, encryption keys, and data exfiltration targets that were intentionally hidden by the obfuscation.
Yes - the JavaScript string unpacker is 100% free with no signup, no account, and no usage limits. Unpack obfuscated strings from any JavaScript code as many times as you need, completely free forever. There are no hidden charges, premium tiers, or usage caps of any kind.