inspired by reversing Discord token stealers
tested on python 3.9.7
but it should work on 3.6+
pip install -U git+https://github.com/unex/nexeDecompiler.git
nexedecompiler
usage: nexedecompiler [-h] [--dest DEST] source
MALWARE$ nexedecompiler LiGzxBbAqEAQ.exe
Writing 6783 files to /MALWARE/LiGzxBbAqEAQ.exe_decompiled
Entrypoint located at /MALWARE/LiGzxBbAqEAQ.exe_decompiled/builds/LiGzxBbAqEAQ.js