ESBuild & JavaScript Decompiler
Reverse-engineer, unminify, unpack bundler IIFEs, expand comma expressions, and restore readable ES6+ JavaScript code.
AST Reverse Engineering & Bundler Decompilation Architecture
Modern JavaScript bundlers (ESBuild, Webpack, Rollup) transform modular source code into heavily minified IIFE closures. Understanding Abstract Syntax Tree (AST) node generation, hex escape decoding, and bundler dispatch helpers allows comprehensive reverse engineering.
__export → ES6 Getter Property Dispatcher
__toESM → CommonJS Interop Shim
__commonJS → Lazy Memoized Closure Cache
Hex Decoder: \\x[0-9a-f]{2} → UTF-8 glyph
Comma Splitting: var a=1,b=2 → Separate statements
Scope Normalization: IIFE Unwrapping
| Bundler Mechanism | Minified Pattern | Decompiled Output | Readability Gain |
|---|---|---|---|
| Property Obfuscation | \\x44\\x6f\\x6e\\x6e | "Done" (Decoded ASCII) | Instant Semantic Clarification |
| ESM Export Shim | var __export=(t,a)=>{...} | function exportModule(target, all) | Modular Architecture Visibility |
| Comma Sequences | return a(),b(),c | a(); b(); return c; | Debugger Step-Through Control |
| Minified Bundle IIFE | (()=>{"use strict";...})() | Beautified AST Scoped Block | Clean Top-Level Code Flow |
5 Critical JavaScript Decompilation Traps
1. The Irreversible Variable Identifier Fallacy
Terser and ESBuild mangle descriptive identifiers (e.g. userAccountBalance) into single-character symbols (a, b, c). Without the original .map source map file, original variable names cannot be algorithmically recovered. Beware of tools promising "100% original source restoration"; true deminification reconstitutes syntactic structure and AST clarity, not lost semantic names.
2. Short-Circuit Conditionals with Mutation Side Effects
Minified code heavily utilizes short-circuit logical operators (ready && init()) and ternary operators (test ? ok() : fail()) instead of if statements. Blindly expanding these into blocks without respecting evaluation short-circuits can accidentally trigger eager function execution or reorder parameter mutations.
3. Regex Literal vs Division Slash Ambiguities
In minified JavaScript, whitespace between operators is eliminated (e.g. a=b/c/d;). Naive regular expression preprocessors often mistake division operators for regular expression literals (/c/). High-precision AST formatting libraries like JS-Beautify track lexer token states to ensure arithmetic slashes are never misparsed as RegExp patterns.
4. Strict Mode Scope Hoisting & Variable Shadowing
Bundlers wrap modules into immediately invoked function expressions with "use strict";. Inside these closures, variables are hoisted according to strict lexical scoping. Unwrapping IIFEs into the global scope without accounting for duplicated minified variable names (e.g. multiple modules using var e) creates global namespace collisions that crash code execution.
5. Memory Overhead on Multi-Megabyte Vendor Bundles
Decompiling a single monolithic 15 MB production bundle with thousands of functions can freeze the browser UI thread if AST line wrapping calculations run synchronously. We recommend decompiling isolated module chunks or using modern developer tools to split bundles before formatting.