The AI tool REA has more than 10,400 stars on GitHub
The binary that the user examines stays on the computer of the user.
On October 7, a developer with the name morluto released REA. REA is an open-source tool that lets a coding agent decompile a binary and tell how it works, with no source code. On the next day, REA had more than 10,400 stars and was first on the GitHub trending page. Days before, CrowdStrike reported that attackers operated a different AI tool, ARTEX, to breach South Korean banks.
What REA does
REA lets a coding agent decompile these items. To decompile is to change a compiled binary back into readable code.
- native binaries
- Electron and JavaScript apps
- .NET assemblies
- websites
The agent then tells how a function works. REA operates from a terminal or in an agent session of Claude Code or Cursor.
The limits
REA does not claim to collect the initial source code or to copy a full software system. Its documentation says that each result has signs and stated caveats. The analysis is on the computer of the user.
The ARTEX case
CrowdStrike reported that an unidentified threat actor operated ARTEX with large language models to breach South Korean financial institutions. ARTEX is an open-source tool for penetration tests. 7 or more banks had a breach, and the data of about 68,000 persons was exposed.
The developer of ARTEX removed the tool from GitHub on October 8.
Sources
Posted