pyinstxtractor-ng
pyinstxtractor-ng is a tool to extract the contents of a Pyinstaller generated executable file. Both Linux ELFs and Windows PE executables are supported.
This project is a fork of pyinstxtractor.
pyinstxtractor-ng uses the xdis library to unmarshal Python bytecode and as a result there is NO requirement to use the same Python version which was used to build the executable.
pyinstxtractor-ng also supports automatic decryption of encrypted pyinstaller executables.
Usage
Precompiled binaries for Linux and Windows are provided in releases. These are generated using PyInstaller itself, so you don't even need a Python installation to run pyinstxtractor-ng
PyInstaller Extractor NG
positional arguments:
filename Path to the file to extract
optional arguments:
-h, --help show this help message and exit
-d, --one-dir One directory mode, extracts the pyz to the same directory
-i, --info Display PyInstaller archive information without extracting files
Pass the exe filename as an argument or drag & drop the pyinstaller exe file over pyinstxtractor.ng icon on Windows.
$ ./pyinstxtractor-ng <filename>
X:\> pyinstxtractor-ng <filename>
The --one-dir mode extracts the pyz in the same directory as the executable. This is useful if you want to run the extracted files straight-away.
X:\> pyinstxtractor-ng --one-dir main.exe
X:\> cd main.exe_extracted
X:\main.exe_extracted\> python main.py
The --info or -i option prints metadata about the PyInstaller archive without writing any extracted files to disk.
This is useful for quick inspection and debugging.
$ ./pyinstxtractor-ng --info <filename>
X:\> pyinstxtractor-ng -i <filename>
See Also
- pyinstxtractor-web: pyinstxtractor running in the web browser, powered by Go & GopherJS.
License
GNU General Public License v3.0
Release files for pyinstxtractor-ng 2026.7.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pyinstxtractor_ng-2026.7.3.tar.gz | 19.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pyinstxtractor_ng-2026.7.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 39.4 kB
Release files / pyinstxtractor_ng-2026.7.3.tar.gz
| Download URL | pyinstxtractor_ng-2026.7.3.tar.gz |
|---|---|
| Size | 19.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
e028984d82939e69f1a6df990b5f48c5ccbd4fef42f67e293f0b90e92fb48171
|
|
BLAKE2b-256 checksum How to use checksums |
97ff6c86f1abe1312f4e9952fbc358fac5d44a6f347cd1438f5f224077590be4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 3, 2026.
Transparency logRelease files / pyinstxtractor_ng-2026.7.3-py3-none-any.whl
| Download URL | pyinstxtractor_ng-2026.7.3-py3-none-any.whl |
|---|---|
| Size | 20.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a381814a03ae7f3c5ae6910bb4ee3a88301916560b49b581a6836e9984fb9873
|
|
BLAKE2b-256 checksum How to use checksums |
dd8d9255543d8c69f3d4407e09fd80c63281758480fafbd2330c508dfc0fc2ac
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 3, 2026.
Transparency log