ChiChou/bagbak
[deprecated] Yet another frida based iOS dumpdecrypted. Also decrypts app extensions observed · 2026-08-28
Health v2 · maintenance only
90/100
- Activity 94
- Release rhythm 79
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 6
- age_days: 3020
- days_rel: 141
- days_push: 40
- n_releases_24m: 8
Adoption not part of the score
1494 stars · 221 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
bagbak is a Node.js CLI tool that uses Frida to decrypt iOS App Store binaries on a jailbroken device, dumping decrypted IPAs including app extensions. It is now deprecated in favor of mremap_encrypted-based approaches that do not require running the target app.
Use cases
- decrypt an iOS app binary from a jailbroken device
- dump a decrypted ipa for reverse engineering
- decrypt app extension binaries on iOS
- list installed apps on a jailbroken iPhone
- remove device restriction keys from an app's Info.plist
- analyze App Store app binaries in a disassembler
When to avoid
- you need a decryptor that does not require running the target app (use mremap_encrypted-based tools like UnFairPlay or unfaird)
- your target app has RASP protections that block runtime dumping
- you have no jailbroken iOS device
Facets
cli-tool · maturity maintenance
reverse-engineering cli security reverse-engineering security apple-ecosystem developer-tools windows cli frida ios-decryptor jailbreak dumpdecrypted app-extensions ipa macos linux ios nodejs
2 sources
- readme: https://github.com/ChiChou/bagbak · fetched 2026-08-28 · 431470d81057
- registry_npm: https://registry.npmjs.org/bagbak · fetched 2026-08-29 · af2e4749690a
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| ChiChou/bagbak | main | 90 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem