JavaScript比特币挖矿混淆代码的解析与还原问题咨询
Great question—let's break this down clearly, since this kind of obfuscation is super common in sketchy crypto-mining scripts:
1) Why does this encoded code still run in browsers?
This trick relies on two native browser JavaScript APIs that are totally legitimate (and widely used for non-malicious purposes too):
atob(): This is a built-in function that decodes a Base64-encoded string back to plain text. Browsers support this natively because Base64 is often used to embed assets like images or send data in APIs.new Function(): This constructor takes a string of JavaScript code and turns it into an executable function. The browser's JS engine parses that string just like it would parse any normal JS code in a script tag.
So in your example:
new Function(atob("dmFyIF8weDg5ZDkgPSBbCiAgImdldEFjY2VwdGVkSGFzaGVzIiwKICAiZ2V0VG9..."))
- First,
atob(...)decodes that long Base64 string into a readable chunk of JavaScript code. - Then
new Function()wraps that decoded string into a function object. If the code calls this function (often with()at the end), the browser runs the decoded JS just like any other script.
It's still valid JS syntax—obfuscation doesn't break the browser's ability to execute it, it just makes it harder for humans to read at a glance.
2) Can this obfuscated code be decoded/reversed?
Absolutely—here are practical methods, depending on how complex the obfuscation is:
Basic case (your example)
- Quick manual decode: Open your browser's developer console (F12 > Console tab), paste the
atob("...")part (just the inside of the new Function call) and hit enter. You'll get the raw decoded JavaScript code immediately. - For example: If you run
atob("dmFyIGE9MTs=")in the console, it'll returnvar a=1;.
More complex obfuscation (nested encoding/extra tricks)
- Browser debugging: Use the Sources panel in dev tools. Set a breakpoint on the
new Functionline, then step through execution. When theatobcall runs, you can inspect the decoded string directly in the debugger's variables pane. - AST-based deobfuscation: For scripts that use multiple layers of encoding (like
atob(atob(...))) or add junk code, you can use tools that parse the JavaScript's Abstract Syntax Tree (AST) to strip out obfuscation. Libraries likeacornoresprima(run via Node.js) can help you parse the code, identify and reverse the encoding steps, and reconstruct clean, readable code. - Avoid anti-debugging tricks: Some malicious scripts try to block debugging (e.g., detecting breakpoints). You can bypass this by disabling debugger statements in your browser's dev tools settings, or using tools that strip anti-debug code before analysis.
Just remember: Always be careful when analyzing untrusted code—never run decoded scripts in your main browser session unless you're in a sandboxed environment!
内容的提问来源于stack exchange,提问作者Maverick

