Skip to main content
Load DLLs and call their exports.
Needs the ffi permission. Addresses here are addresses in the cheat’s own process: bigint, with null for NULL. Game memory is Pointer.

Overview

Libraries

open, func, funcAsync, funcs, symbol, dispose.

Signatures

Type names, strings, out params, variadics.

Structs

struct, union, typedef, sizeOf, views.

Callbacks

callback.

Memory helpers

alloc, free, readString, lastError, …

Libraries

open


Loads a DLL. Bare names use the normal DLL search order. Throws ENOENT when it isn’t found.

func


Binds an export as a JS function. Throws ENOENT for a missing export. The type parameter only types the result; the signature decides the conversion. A crash inside the native call throws EFAULT.

funcAsync


Like func, but each call runs in the background and returns a Promise. _Out_ holders are filled before it resolves. ffi.lastError() doesn’t see async calls.

funcs


Binds several exports at once. The export name is the one in the signature, or the key when the signature has none. Throws on the first one that fails.

symbol


The address of an export, or null when there isn’t one.

dispose


Unloads the library. Functions bound from it throw ESTALE afterwards. using does it at the end of the block.

Signatures

Parameter names are optional. Calling conventions are accepted and ignored. long is 32-bit (Windows). const, struct X, enum X (an int), the Win32 pointer aliases (LPDWORD, PHANDLE, …) and your own typedef/struct names work too. Unknown names throw TypeError. Strings. A JS string passed to a string parameter is only valid during the call. String parameters also take a buffer the function writes into. Numbers, bigints and booleans aren’t coerced. Pointer arguments take a bigint, null, a BufferSource or struct view, a Pointer or a Callback.

Out parameters

_Out_ / _Inout_ pointers to a scalar or pointer take a { value } holder. _Inout_ sends value, both set it after the call. A T* to a struct also takes a plain object; with _Out_ / _Inout_ its fields are written back.

Variadics

A trailing ... makes the function variadic. Pass each extra argument as a (typeName, value) pair; float is promoted to double.

Structs by value

A struct name without * passes the struct by value. A by-value return is a new struct view.

Structs

struct


Defines a C struct, laid out in field order with C alignment. A named struct can then be used by name in this script’s signatures, fields and typedefs.
In struct fields char* is a raw pointer, never a string; inline text is char[N] (UTF-8) or wchar_t[N] (UTF-16). Numeric arrays are typed arrays, pointer arrays a BigUint64Array. The same StructType objects come from memory.struct without the ffi permission, for reading game memory.

union, typedef, sizeOf

StructType

view and decode take a bigint address, a BufferSource or another view. offset must be a multiple of alignment.
A bigint address is trusted as is: view(address) doesn’t copy, so the memory must stay valid while you use the view.

Views

Fields of a view read and write the memory directly. Besides its fields a view has:

Callbacks

callback


Exposes fn as a native function pointer. Pass the Callback (or its address) wherever a function pointer goes. String arguments arrive as string | null. A callback can’t return a string (return ptr) and can’t be variadic.
If fn throws, native code gets 0 and the error goes to the global error event.
fn only runs synchronously when native code calls it during one of your own synchronous FFI calls (like EnumWindows). Called any other time, such as from another thread, a void callback runs on the next tick and any other callback returns 0.

Memory helpers


Example

Titles of all visible top-level windows.