Forwarded from 在花🎗️科技圈
Nekogram 12.5.2 被曝存在后门,静默窃取用户手机号
安全研究人员发现第三方 Telegram 客户端 Nekogram 12.5.2(Google Play 版)内置后门代码,会在用户不知情的情况下收集所有已登录账号的手机号,并通过 Inline Query 外传至开发者控制的 Bot(@nekonotificationbot)。
后门代码位于 Extra.java(混淆后为 uo5),核心逻辑:遍历 8 个账号槽位 → 提取 UserID 与手机号 → 拼接密钥后以 Inline Query 发送。所有关键字符串均经自定义加密混淆。
该后门仅存在于编译发布的 APK 中,GitHub 公开源码中的对应文件为无害占位。经独立反编译对比验证,从源码自行编译的版本不含上述后门组件。
开发者回应称 Bot 仅用于"解析用户名",但代码中明确提取了 phone 字段并使用无痕传输方式,与其说辞不符。
报告
via 群友投稿
🌸 在花频道|茶馆讨论|投稿通道
安全研究人员发现第三方 Telegram 客户端 Nekogram 12.5.2(Google Play 版)内置后门代码,会在用户不知情的情况下收集所有已登录账号的手机号,并通过 Inline Query 外传至开发者控制的 Bot(@nekonotificationbot)。
后门代码位于 Extra.java(混淆后为 uo5),核心逻辑:遍历 8 个账号槽位 → 提取 UserID 与手机号 → 拼接密钥后以 Inline Query 发送。所有关键字符串均经自定义加密混淆。
该后门仅存在于编译发布的 APK 中,GitHub 公开源码中的对应文件为无害占位。经独立反编译对比验证,从源码自行编译的版本不含上述后门组件。
开发者回应称 Bot 仅用于"解析用户名",但代码中明确提取了 phone 字段并使用无痕传输方式,与其说辞不符。
报告
via 群友投稿
🌸 在花频道|茶馆讨论|投稿通道
😱170😁56❤16👍5🎉3💔3😡2👏1🌭1
Forwarded from WAuxiliary CI Builds
This media is not supported in your browser
VIEW IN TELEGRAM
注意
MT/NP 的 Dex字符串解密 功能
在解密恶意软件时存在部分风险
建议在虚拟机中运行以加强防护
WA开发团队
2026.04.04
MT/NP 的 Dex字符串解密 功能
在解密恶意软件时存在部分风险
建议在虚拟机中运行以加强防护
WA开发团队
2026.04.04
😱158❤17👀6🥰3🌚3🤔1
Forwarded from LSPosed
LSPosed-v2.0.2-7668-release.zip
11.1 MB
Changes since last release:
Added
Enabled dynamic blur based on device state (e.g. power saving mode, performance class)
Added collapsing for long module descriptions
Added tapjacking mitigation toggle and hint
Hid the "install to other user" option when the module is already installed
Improved
Reduced per-method callback count to limit crash propagation caused by faulty modules
Ensured Xposed service is re-delivered after module updates
Sent binder to daemon earlier during system boot to reduce initialization race conditions
Removed the need to force stop when switching manager
Updated LSPlant to fix various injection issues
Updated MIUIX to address known issues
Optimized memory usage during manager startup and repository loading for low-RAM devices
Fixed
Fixed incorrect "install to user" behavior in the new manager
Fixed module configuration not being removed on uninstall
Fixed rare cases where hooks were not updated after module upgrade
Fixed native API loading timing for the new API
Fixed excessive memory usage during manager startup and repository loading
Fixed search results being obscured by the bottom bar
Fixed edge-to-edge layout issues in the new manager
新增
新管理器根据设备状态(如省电模式、性能等级)动态决定是否启用模糊效果
新管理器支持折叠过长的模块描述
新增点按劫持(tapjacking)缓解开关及提示
当模块已安装时,新管理器隐藏“安装到其他用户”的选项
改进
减少每个方法的最大回调数量,降低异常模块导致的系统崩溃扩散风险
确保模块更新后重新分发 Xposed 服务
系统启动阶段更早向 daemon 发送 binder,减少初始化竞态窗口
切换管理器无需再强行停止进程
更新 LSPlant,修复多类注入与 hook 相关问题
更新 MIUIX,修复已知兼容性问题
优化管理器启动及模块仓库加载时的内存占用
修复
修复新管理器“安装到用户”选项异常
修复卸载模块时未清理配置的问题
修复模块更新后在极少数情况下 hook 未生效的问题(如更新后立即强制停止目标应用)
修复新 API 的 native API 加载时机问题
修复管理器启动及加载模块仓库时的内存占用异常
修复搜索结果被底栏遮挡的问题(窗口 inset 处理)
修复新管理器边到边布局问题
20❤47🥰5😁2👍1
LuckyTool 1.3.4
其他链接 (Other Links)
禁止引流、搬运、转载、售卖、分享、分流
[模块文档 ModuleDoc] https://luckyzyx.gitlab.io/LuckyTool_Doc
[反馈流程 FeedbackProcess] https://luckyzyx.gitlab.io/LuckyTool_Doc/check_problem
[下载方式 DownloadLink] https://luckyzyx.gitlab.io/LuckyTool_Doc/use/download_link
[捐赠方式 Donate] https://luckyzyx.gitlab.io/LuckyTool_Doc/donate
[捐赠方式 腾讯文档] https://docs.qq.com/doc/DS2ZDZlNIeUlpdlV1
更新日志 (ChangeLog)
[修复] 模块内置检测更新异常
[修复] 自动检测更新开关异常
[更改] 更改多浮窗最大数量为20
[添加] 自动跳转无障碍设置
[添加] 禁用截图包名MD5加密
[添加] 移除开始录制或投射对话框
[添加] 强制显示Toast提示图标
[适配] 自定义OTA更新卡片背景 v16.0.0(ec38064)
[添加] 禁用音量条粗细效果 C14+
[更改] 同步上游核心破解v4.9
[更改] 同步上游DisableFlagSecure v5.0.1
[添加] 解锁工程模式部分隐藏选项
[添加] 启用音量条百分比显示
[添加] 启用控制中心进度条百分比显示
[适配] 锁屏充电组件瓦数显示 v16.00.12(160012)
[添加] 自定义音量条百分比颜色
[添加] 自定义控制中心进度条百分比颜色
[适配] 隐藏OTA卡片顶层文本 v16.0.0(ec38064)
[适配] ColorOS V16.1.0, V17.0.0 版本名称显示
[适配] 移除桌面图标徽标 v16.6.5(37c6638)
[适配] 软件商店启动页广告 v26.1.2_CN(60d4105)
[适配] 移除电池限制插件 v1.2.8(aeabc11)
[适配] 智能侧边栏后台挂机 v16.12.2(3fd0d0c)
[适配] 显示Apk更多安装信息 v16.0.3(a6eac93)
[适配] 应用分身最大数量限制 C16.1
[修复] 桌面卡片名称崩溃问题
[适配] 移除免打扰模式通知 C16.1
[适配] 移除锁屏时钟红一 C16.1
[适配] 移除Docker数量限制 C16.1
[Fix] Module built-in detection update abnormality
[Fix] Automatically detect update switch abnormality
[Change] Change the maximum number of multi-floating windows to 20
[Add] Automatically jump to accessibility settings
[Add] Disable MD5 encryption of screenshot package name
[Add] Remove start recording or casting dialog
[Add] Forced display of Toast prompt icon
[Fix] Customize OTA update card background v16.0.0(ec38064)
[Add] Disable volume bar thickness effect C14+
[Change] Sync upstream core crack v4.9
[Change] Sync upstream DisableFlagSecure v5.0.1
[Add] Unlock some hidden options in engineering mode
[Add] Enable volume bar percentage display
[Add] Enable control center progress bar percentage display
[Fix] Lock screen charging component wattage display v16.00.12(160012)
[Add] Custom volume bar percentage color
[Add] Customize control center progress bar percentage color
[Fix] Hide OTA card top text v16.0.0(ec38064)
[Fix] ColorOS V16.1.0, V17.0.0 version name display
[Fix] Remove desktop icon logo v16.6.5(37c6638)
[Fix] Software store startup page advertisement v26.1.2_CN(60d4105)
[Fix] Remove battery limit plug-in v1.2.8(aeabc11)
[Fix] Smart sidebar background hangup v16.12.2 (3fd0d0c)
[Fix] Show more installation information of Apk v16.0.3(a6eac93)
[Fix] Limit on the maximum number of application clones C16.1
[Fix] Desktop card name crash issue
[Fix] Remove Do Not Disturb mode notification C16.1
[Fix] Remove lock screen clock red one C16.1
[Fix] Remove Docker quantity limit C16.1
其他链接 (Other Links)
禁止引流、搬运、转载、售卖、分享、分流
[模块文档 ModuleDoc] https://luckyzyx.gitlab.io/LuckyTool_Doc
[反馈流程 FeedbackProcess] https://luckyzyx.gitlab.io/LuckyTool_Doc/check_problem
[下载方式 DownloadLink] https://luckyzyx.gitlab.io/LuckyTool_Doc/use/download_link
[捐赠方式 Donate] https://luckyzyx.gitlab.io/LuckyTool_Doc/donate
[捐赠方式 腾讯文档] https://docs.qq.com/doc/DS2ZDZlNIeUlpdlV1
更新日志 (ChangeLog)
[修复] 模块内置检测更新异常
[修复] 自动检测更新开关异常
[更改] 更改多浮窗最大数量为20
[添加] 自动跳转无障碍设置
[添加] 禁用截图包名MD5加密
[添加] 移除开始录制或投射对话框
[添加] 强制显示Toast提示图标
[适配] 自定义OTA更新卡片背景 v16.0.0(ec38064)
[添加] 禁用音量条粗细效果 C14+
[更改] 同步上游核心破解v4.9
[更改] 同步上游DisableFlagSecure v5.0.1
[添加] 解锁工程模式部分隐藏选项
[添加] 启用音量条百分比显示
[添加] 启用控制中心进度条百分比显示
[适配] 锁屏充电组件瓦数显示 v16.00.12(160012)
[添加] 自定义音量条百分比颜色
[添加] 自定义控制中心进度条百分比颜色
[适配] 隐藏OTA卡片顶层文本 v16.0.0(ec38064)
[适配] ColorOS V16.1.0, V17.0.0 版本名称显示
[适配] 移除桌面图标徽标 v16.6.5(37c6638)
[适配] 软件商店启动页广告 v26.1.2_CN(60d4105)
[适配] 移除电池限制插件 v1.2.8(aeabc11)
[适配] 智能侧边栏后台挂机 v16.12.2(3fd0d0c)
[适配] 显示Apk更多安装信息 v16.0.3(a6eac93)
[适配] 应用分身最大数量限制 C16.1
[修复] 桌面卡片名称崩溃问题
[适配] 移除免打扰模式通知 C16.1
[适配] 移除锁屏时钟红一 C16.1
[适配] 移除Docker数量限制 C16.1
[Fix] Module built-in detection update abnormality
[Fix] Automatically detect update switch abnormality
[Change] Change the maximum number of multi-floating windows to 20
[Add] Automatically jump to accessibility settings
[Add] Disable MD5 encryption of screenshot package name
[Add] Remove start recording or casting dialog
[Add] Forced display of Toast prompt icon
[Fix] Customize OTA update card background v16.0.0(ec38064)
[Add] Disable volume bar thickness effect C14+
[Change] Sync upstream core crack v4.9
[Change] Sync upstream DisableFlagSecure v5.0.1
[Add] Unlock some hidden options in engineering mode
[Add] Enable volume bar percentage display
[Add] Enable control center progress bar percentage display
[Fix] Lock screen charging component wattage display v16.00.12(160012)
[Add] Custom volume bar percentage color
[Add] Customize control center progress bar percentage color
[Fix] Hide OTA card top text v16.0.0(ec38064)
[Fix] ColorOS V16.1.0, V17.0.0 version name display
[Fix] Remove desktop icon logo v16.6.5(37c6638)
[Fix] Software store startup page advertisement v26.1.2_CN(60d4105)
[Fix] Remove battery limit plug-in v1.2.8(aeabc11)
[Fix] Smart sidebar background hangup v16.12.2 (3fd0d0c)
[Fix] Show more installation information of Apk v16.0.3(a6eac93)
[Fix] Limit on the maximum number of application clones C16.1
[Fix] Desktop card name crash issue
[Fix] Remove Do Not Disturb mode notification C16.1
[Fix] Remove lock screen clock red one C16.1
[Fix] Remove Docker quantity limit C16.1
LuckyTool
首页
对ColorOS系统进行的扩展优化的Xposed模块
30❤204👍25🥰6👏6😱2
Forwarded from LSPosed
v2.0.3 released:
v2.0.3 发布:
Download / 下载:
Major Behavioral Changes
- Legacy modules are no longer allowed to call libxposed API; modules with targetApiVersion ≥ 102 will not be allowed to call legacy API; 101 modules are unaffected
New Features
- Introduced Material 3 Expressive style manager
- Enhanced theme-related settings to support dynamic color schemes and dark mode, and improved the display of cards, menus, bottom navigation, and dialogs
Improvements
- Improved log display and error logging; parsed view now correctly displays excessively long error stacks without fragmentation
- Attempted to improve hook performance
Fixes
- Fixed an issue where scope recommendations were displayed incorrectly in some legacy modules
- Fixed several issues with libxposed API implementations
Removals
- Removed the old MD3 manager
- Removed support for the 32-bit x86 architecture
v2.0.3 发布:
重大行为变更
- Legacy 模块不再允许调用 libxposed API;targetApiVersion ≥ 102 的模块不再允许调用 Legacy API,101 模块不受影响
新增
- 引入 Material 3 Expressive 风格管理器
- 完善主题相关设置,支持动态配色和深色模式,改进卡片、菜单、底部导航和对话框的显示效果
改进
- 改进日志显示和错误记录,现在解析视图能够正确显示超长错误栈而不被分片
- 尝试改进 hook 性能
修复
- 修复部分旧模块作用域推荐显示错误的问题
- 修复一些 libxposed API 实现问题
移除
- 移除旧的 MD3 管理器
- 移除 32 位 x86 架构支持
Download / 下载:
👍41❤16
Forwarded from LSPosed
LSPosed-v2.0.4-7741-release.zip
8.4 MB
Changes since latest release:
自上次更新以来的改动:
Added
- Provided high-speed CDN for the module repository. If you dislike ads, please switch to backup CDN in settings
- Added SystemUI safe mode
Improved
- Enhanced hook compatibility and performance
- Improved homepage device name recognition
Fixed
- Fixed Android 17 QPR1 Beta 3 crash issues
- Fixed a series of M3E theme-related issues
- Fixed Markdown WebView reload handling issues
自上次更新以来的改动:
新增
- 提供模块仓库高速 CDN,若不喜欢广告请在设置切换备用 CDN
- 新增 SystemUI 安全模式
改进
- 提升 hook 兼容性和性能
- 增强首页设备名称识别
修复
- 修复 Android 17 QPR1 Beta 3 崩溃问题
- 修复一系列 M3E 主题相关问题
- 修复 Markdown WebView 重载处理问题
🥰37❤18
Forwarded from LSPosed
v2.1.0
下载 / Download
新增
实现 libxposed API 102
适配 Android 17 QPR1 Beta 4
维护
原计划 2.1.0 废弃 New XSharedPreferences 推迟到 2.2.0,强烈建议 legacy 模块尽快迁移到 libxposed
今后可向 report@bug.lsposed.org 发送反馈邮件
改进
大幅提升被 hook 方法的性能
优化还原内联钩子逻辑
优化 dex 优化器包装的挂载逻辑
优化一系列的 UI 体验
修复
修复 XposedBridge.unhookMethod 行为异常
修复了一个全局检测点
修复 TalkBack 重复朗读、未朗读勾选状态等无障碍问题
Added
Implemented libxposed API 102
Adapted for Android 17 QPR1 Beta 4
Maintaince
Postponed the planned deprecation of New XSharedPreferences in version 2.1.0 to 2.2.0. We strongly recommend migrating legacy modules to libxposed as soon as possible
Feedback is now available by emailing to report@bug.lsposed.org
Improved
Significantly improved the performance of hooked methods
Optimized invalidate inline hooks logic
Optimized the mount logic of dex optimizer wrapper
Optimized a range of UI experiences
Fixed
Fixed abnormal behavior of XposedBridge.unhookMethod
Fixed a global detection point
Fixed accessibility issues such as TalkBack repeating text and failing to read checked items
下载 / Download
👍56❤12😢2😁1
Forwarded from LSPosed
v2.1.1
新增
- 最低支持版本提升至 Android 9(API 28)
- 高级隐藏功能现可支持 A12+
- 允许一键清空已选作用域
改进
- 优化安全模式对 System UI 的检测阈值
- 恢复管理器中的模块数量徽标
- 改进错误报告发送流程
修复
- 修复部分情况下无法启动守护进程的问题
- 修复 XposedHelpers.findField API 行为
- 修复 Android 17 下服务连接接口不兼容的问题
- 修复模块详情页弹出菜单显示层级异常的问题
- 修复 Markdown 样式在部分页面中显示异常的问题
Added
- Raised the minimum supported version to Android 9 (API 28)
- Advanced hiding is now supported on Android 12 and above
- Added an option to clear all selected scope apps
Improved
- Optimized the System UI detection threshold in safe mode
- Restored the module count badge in the manager
- Improved the error report submission process
Fixed
- Fixed an issue that could prevent the daemon from starting
- Fixed the behavior of the XposedHelpers.findField API
- Fixed service connection incompatibility on Android 17
- Fixed incorrect popup menu layering on the module details page
- Fixed Markdown styles being displayed incorrectly on some pages
1👏28❤4👍2
Forwarded from ColorOS Pro
一加社区
一加手机官方论坛。一加手机开箱体验、测评报告、玩机技巧、手游攻略。与你分享美图及摄影技巧,众多大神教你轻松刷机,并由丰富手机资源任由下载。百万加油大家庭,交流更随心,一加社区官方论坛
😭45😁8👍4❤3🌚2🤔1
Forwarded from 不靠谱的喵(>^ω^<) #CatGPT (Yuze Wu 🐱 | 女子大学生 | 喵!)
一加调整国行 BootLoader 解锁深度测试规则:
搭载 ColorOS 16 及以上版本的机型、升级至 ColorOS 17 及以上版本的机型,可通过官方通道申请加入深度测试计划。未满足上述条件的 ColorOS 版本机型, Bootloader 解锁不受影响。
已支持深度测试的机型将于 9 月优先采用该政策;搭载或升级至 ColorOS 17 及以上版本的机型将结合新机发布、ColorOS 17 正式版推送节奏分批纳入。
已支持深度测试的机型:将于 9 月首次开放名额,次月开始每月 1 日释放名额
搭载 ColorOS 17 及以上版本的机型:将于新机发布会满一个月后首次开放名额,次月开始每月 1 日释放名额
升级至 ColorOS 17 及以上版本的机型:将于正式版推送满一个月后首次开放名额,次月开始每月 1 日释放名额
搭载 ColorOS 16 及以上版本的机型、升级至 ColorOS 17 及以上版本的机型,可通过官方通道申请加入深度测试计划。未满足上述条件的 ColorOS 版本机型, Bootloader 解锁不受影响。
已支持深度测试的机型将于 9 月优先采用该政策;搭载或升级至 ColorOS 17 及以上版本的机型将结合新机发布、ColorOS 17 正式版推送节奏分批纳入。
已支持深度测试的机型:将于 9 月首次开放名额,次月开始每月 1 日释放名额
搭载 ColorOS 17 及以上版本的机型:将于新机发布会满一个月后首次开放名额,次月开始每月 1 日释放名额
升级至 ColorOS 17 及以上版本的机型:将于正式版推送满一个月后首次开放名额,次月开始每月 1 日释放名额
😡153❤18😁9👻5😭4👍3🍾3
Forwarded from LSPosed
v2.2.0
重要
- New XSharedPreferences 计划于 2.3.0 正式移除,模块页面已为有兼容风险的模块加入废弃警告。判断逻辑为 legacy 模块声明支持 nsp 并存在 others 可读 xml。升级到 libxposed 或将 xposedminversion 设置为 82 并删除 xposedsharedprefs 以移除警告。
新增
- 支持注入 HyperOS Runtime 应用(需要兼容 Zygisk Next API 的 Zygisk 实现)
- 在 A17 及以上以注入方式处理 dex2oat 包装器,避免挂载泄漏(需要兼容 Zygisk Next API 的 Zygisk 实现)
改进
- 提升多进程应用中模块服务连接的稳定性
- 优化管理器中的兼容性状态展示与异常提示
修复
- 修复资源 Hook XML 重写长期失效的问题
- 修复模块热重载失败后可能产生状态异常的问题
- 修复 Hook 链调用及参数类型转换问题
- 修复系统框架在模块作用域中的排序
- 修复安全模式计数未在正常启动后重置的问题
- 修复 Dex 混淆及模块服务相关的内存泄漏
Important
- New XSharedPreferences is scheduled for official removal in version 2.3.0. Deprecation warnings have been added to the module page for modules at risk of compatibility issues. The probe logic identifies legacy modules that declare support for nsp and contain an XML file with others readable permission. To eliminate the warning, upgrade to libxposed or set xposedminversion to 82 and remove xposedsharedprefs.
Added
- Support for injecting into HyperOS Runtime apps (requires Zygisk implementation which is compatible with Zygisk Next API)
- Handles the dex2oat wrapper via injection on A17 and above to prevent mount leaks (requires Zygisk implementation which is compatible with Zygisk Next API)
Improved
- Improved stability of module service connections in multi-process apps
- Optimized the display of compatibility status and error prompts in the Manager
Fixed
- Fixed an issue where resource hook XML rewriting had been failing for an extended period
- Fixed an issue where a status exception might occur after a module hot reload failed
- Fixed issues with hook chain calls and parameter type conversions
- Fixed the sorting of the system framework within the module scope
- Fixed an issue where the safe mode count was not reset after a normal startup
- Fixed memory leaks related to DEX obfuscation and module services
👍17❤7👻2☃1
LSPosed
v2.2.0 重要 - New XSharedPreferences 计划于 2.3.0 正式移除,模块页面已为有兼容风险的模块加入废弃警告。判断逻辑为 legacy 模块声明支持 nsp 并存在 others 可读 xml。升级到 libxposed 或将 xposedminversion 设置为 82 并删除 xposedsharedprefs 以移除警告。 新增 - 支持注入 HyperOS Runtime 应用(需要兼容 Zygisk Next API 的 Zygisk 实现) - 在 A17 及以上以注入方式处理…
更新此版本后出现的legacy提示可以忽略,在v2.3.0之前不影响功能使用,后期正在准备适配迁移libxpsoed 102,敬请期待!
1👍170❤16🥰9👻5👏2🔥1