OnionHEN: an all-in-one HEN and Toolbox for jailbroken PS5

OnionHEN bundles HEN, a ShellUI Toolbox, plugins and cheats for jailbroken PS5. Here's what it needs and how the startup chain works.

olya_nro2026-10-07· scout:gh

OnionHEN is an all-in-one HEN and Toolbox for jailbroken PS5 consoles, and the project lives on GitHub under aydencharles. It puts a settings page into ShellUI and bundles kstuff for homebrew SELF and PKG, a plugin runtime, a payload manager, an in-game overlay and a cheat engine. If you’ve been juggling separate tools for each job, this is one install instead.

It’s a payload stack, not an exploit. The README says there’s no kernel exploit in the package, so the first hop is still yours to handle. You need an external elfldr listening on port 9021. After that, OnionHEN starts its own loader on 9020 for later ELF and user-payload launches and keeps 9021 as a fallback.

The extras are the reason to look twice. There’s an FTP server, ShadowMount+, and DPI v2, a network package installer with a browser UI on port 12800 by default. Remote Play pairing is in there too, but it needs your account activated first, and video still runs through Sony’s native service. Cheats are JSON, SHN, MC4 or ShnExt files named by title ID and version, and they reload from disk without restarting the whole stack.

How to try it:

  1. Get a jailbroken PS5 and start the kernel exploit and the external elfldr service from your exploit host.
  2. Send OnionHEN.elf through the loader your exploit host provides.
  3. Wait for the utility daemon, kstuff and the main daemon to start, in that order.
  4. Open PS5 Settings and enter the OnionHEN Toolbox.

The caveats: the README doesn’t list which firmware versions it supports, so check with your exploit host before you run anything. Startup is sequential, so give it time and don’t yank the power. Plugins go in /data/OnionHEN/plugins/ and standalone payloads in /data/OnionHEN/payloads/. If you want to build from source, you need the PS5 Payload SDK, CMake 3.20+, Ninja and Clang/LLVM, or you can use the Docker build. I’d treat this as the layer you add once your exploit already works, not as a way in.

Sources: github.com