Why you should stop using Nekogram

TunogLata

Forum Veteran
BREAKING: Nekogram is secretly sending your phone numbers to the developer.
The backdoor is hidden in the Extra.java file, which differs from the template uploaded to the repository. The obfuscated code sends data as an inline request to @nekonotificationbot, leaving no trace.

More info: You do not have permission to view the full content of this post. Log in or register now.
(locked by Nekogram devs)
To validate this, a developer built a PoC — an LSPosed module that replaces the bot ID and username to theirs, redirecting all requests to it. This independently confirmed that phone numbers are being collected. Every. Login.

PoC available here:
You do not have permission to view the full content of this post. Log in or register now.

The developer's response when confronted:
51396.webp
51395.webp


Screenshots:
51393.webp
51394.webp
 
fully archive all the conversations, commit logs, issue #336 from their official repo, fork/clone the entire repo itself, the release builds connected to the malicious commit, and try to reach out some social influencers that may help publicly expose these kind of stuff. Sa youtube dami mahilig mag expose ng ganyang open source projects na may malicious code
 

Similar threads

About this Thread

  • 4
    Replies
  • 299
    Views
  • 5
    Participants
Last reply from:
Hazama

Trending Topics

Online now

Members online
791
Guests online
1,223
Total visitors
2,014

Forum statistics

Threads
2,274,086
Posts
28,953,569
Members
1,235,055
Latest member
tayraleyt
Back
Top