SReverseby Simpa Labs

React Native

Reading React Native code when the bundle is unreadable

The file is there and no editor makes sense of it, or the path you expected is empty. React Native bundles arrive in several forms, and only one of them is plain JavaScript.

Five states that all look unreadable

A React Native bundle is JavaScript that has usually been minified, and a release build frequently compiles it to Hermes bytecode as well. On top of that the file can be compressed, encoded, renamed, or absent from the package because the app downloads it after installation. Each state needs a different first move, and identifying the state is faster than trying tools at random.

  • Minified JavaScript is readable. The names are short and the file has no line breaks, so a formatter restores the structure and the request logic becomes legible.
  • A Hermes bytecode file is a binary program. It begins with a header, a parser rejects it, and the strings have to be read from a string table instead.
  • A compressed or encoded bundle needs a container step. The bytes after the header are not the bundle, and the first bytes say whether the container is a common compression format or something the app unpacks itself.
  • A bundle missing from the APK was fetched at run time. Update services exist so that the running JavaScript can be newer than the installed package.
  • A renamed or relocated bundle still loads. The path is a build setting, so searching for the default name and stopping is how a bundle gets missed.

Start with the first bytes and the file list

Begin by listing every asset in the package and looking for a file of the right size, because a bundle is among the largest files in a React Native app and its size is a reliable signal even when its name is not. That list also shows when two bundles exist, which happens during a migration from a plain bundle to a compiled one.

Reading the first bytes is a two-minute test that removes most of the guesswork. A file that begins with printable JavaScript continues as JavaScript, a file that begins with a compression marker needs unpacking before anything else, and a file whose first bytes are a binary structure with a version number is a compiled bundle. Then compare the file against a capture: when an endpoint from the traffic appears in the bundle as text, the file you hold is the code you are looking for and the extraction can proceed.

When the bundle is fetched after installation

A build configured for over the air updates ships a bootstrap bundle and downloads the current one on first run. The downloaded copy is the code that runs, and it is stored in the app's private data directory on the device. Pull it from the device rather than from the APK, then read the download address recorded in the package, because a configuration that points at a preview channel changes the code you get.

When the strings have been encoded

A bundle that is readable in structure and useless in content has had its strings transformed. The transformation is applied by a module inside the bundle or by a native component the bundle calls, and the reversal has two routes.

  • Find the decode routine in the bundle. A string table held as an array of encoded values behind an index function is a common pattern, and the array and the function are both in the file you already have.
  • Read decoded values from the running app. Place an observation point after the decode step and record the plaintext as the app uses it, which avoids reimplementing the decoder at all.

Working order

Identify the state, then follow the state to its tool. A formatted plain bundle goes straight to a search for endpoints and the HTTP wrapper. Bytecode goes to a disassembler and a string extraction. A container goes to a decompression step first. A missing bundle goes to the device. Once the code is readable the work matches any other React Native app: find the request construction, reproduce it, and verify against the server.

Deliverables for that work are a Python, JavaScript or TypeScript client, an importable Postman collection and documentation, starting at $120 with most projects finished in 24 to 72 hours.

Reviewed 28 September 2026 · SReverse research desk

Start your full APK reconstruction

Send the full APK

Projects start at $120. Choose WhatsApp or email, then attach the APK in the app that opens. We reply within one hour with the next step and send the fixed quote after review.

Want us to contact you?