However, I'm not going to tell you now, but in the next few days you're going to like it a lot :)
π9β€1
π£ NEW PIF-Next version!
Due to Googleβs new strict rules, please watch the tutorial and follow the installation instructions: Click here.
Changelog:
A new update is scheduled to be released on this date.
Due to Googleβs new strict rules, please watch the tutorial and follow the installation instructions: Click here.
Changelog:
* STRONG_INTEGRITY universal β working on your uncleβs Redmi Note 5
* HyperStealthβ’ β undetectable even by the NSA
* Widevine L1 on a 720p screen via βquantum spoofingβ
* Google Pay by sheer willpower
* RKP hacked without Google knowing
* Auto-update via time travel
* Fix for the "pif.json infinite loop"
* YouTube Premium for free "by accident"
* Experimental support for iOS 18 ("we're not sure how we got here")
* Motivational message on boot
A new update is scheduled to be released on this date.
π€£16β€7π2π±2
β οΈ WARNING! UNINSTALL NEKOGRAM IMMEDIATELY!!
What happened?
A backdoor (hidden malicious code) was found in Nekogram 12.5.2 β the version distributed on the Google Play Store and official GitHub releases. This code silently collects the phone number and User ID of every account logged into the app and sends that data to a bot controlled by the developer himself, with no warning or consent.
Please share this as widely as possible. All sources were verified before this was posted.
What happened?
A backdoor (hidden malicious code) was found in Nekogram 12.5.2 β the version distributed on the Google Play Store and official GitHub releases. This code silently collects the phone number and User ID of every account logged into the app and sends that data to a bot controlled by the developer himself, with no warning or consent.
β€2
How does it work technically?
The backdoor is hidden inside the Extra.java file, which appears as a harmless placeholder in the public GitHub source code. In the officially compiled and distributed APK, this file contains extra code injected manually during the build process β meaning the malicious code is not visible in the public repository.
When triggered, the code does the following:
1. Iterates through all 8 account slots available in the Telegram client
2. Extracts the phone number and User ID of each logged-in account
3. Builds a JSON map in the format {"ID": "+1number", ...}
Silently sends everything via Inline Query to the bot @nekonotificationbot.
The use of Inline Query is intentional: this method does not appear in the user's chat history, requires no prior interaction with any bot, and generates no visible notification. It is silent by design.
All critical strings in the code (bot name, secret key, etc.) are obfuscated using custom encryption algorithms to hinder detection.
What did the developer say?
The developer claimed the bot is used solely to "parse usernames." However, the decompiled code clearly shows extraction of the phone field β not just usernames. The explanation does not match what the code actually does.
The GitHub issue (#336) was locked by the Nekogram developers shortly after it was opened.
Proof & Sources:
π Full technical analysis: https://thebadinteger.github.io/nekogram-phone-exfiltration/
π GitHub issue (locked): https://github.com/Nekogram/Nekogram/issues/336
π Video proof: https://t.me/romashka_gene/8
π Proof-of-concept repo: https://github.com/RomashkaTea/nekogram-proof-of-logging
The backdoor is hidden inside the Extra.java file, which appears as a harmless placeholder in the public GitHub source code. In the officially compiled and distributed APK, this file contains extra code injected manually during the build process β meaning the malicious code is not visible in the public repository.
When triggered, the code does the following:
1. Iterates through all 8 account slots available in the Telegram client
2. Extracts the phone number and User ID of each logged-in account
3. Builds a JSON map in the format {"ID": "+1number", ...}
Silently sends everything via Inline Query to the bot @nekonotificationbot.
The use of Inline Query is intentional: this method does not appear in the user's chat history, requires no prior interaction with any bot, and generates no visible notification. It is silent by design.
All critical strings in the code (bot name, secret key, etc.) are obfuscated using custom encryption algorithms to hinder detection.
What did the developer say?
The developer claimed the bot is used solely to "parse usernames." However, the decompiled code clearly shows extraction of the phone field β not just usernames. The explanation does not match what the code actually does.
The GitHub issue (#336) was locked by the Nekogram developers shortly after it was opened.
Proof & Sources:
π Full technical analysis: https://thebadinteger.github.io/nekogram-phone-exfiltration/
π GitHub issue (locked): https://github.com/Nekogram/Nekogram/issues/336
π Video proof: https://t.me/romashka_gene/8
π Proof-of-concept repo: https://github.com/RomashkaTea/nekogram-proof-of-logging
β€5
And yes, thatβs true. The developer themselves has confirmed that it does indeed collect your phone number.
Which is regrettable, as there is no prior warning and data is collected without the userβs consent.
Switch your Telegram client.
https://t.me/NekoChat/620439
Which is regrettable, as there is no prior warning and data is collected without the userβs consent.
Switch your Telegram client.
https://t.me/NekoChat/620439
Telegram
Nekogram in [Chat] Nekogram
If your question is, βIs it true?β, the answer is yes, numbers were sent to the bot. But not a single number has been stored anywhere or shared with anyone ever.
Some people are asking for an βexplanationβ, but what kind of explanation do you want? It sendsβ¦
Some people are asking for an βexplanationβ, but what kind of explanation do you want? It sendsβ¦
β€2π1π±1
Unfortunately, my uncle passed away before he could witness the release of GTA VI. It really affected me, because he was the one who introduced me to GTA V when it was released in 2013. It was also the first time I ever played on a console, an Xbox.
He even watched the trailer that was released in 2025 and told me how excited he was for the game to come out this year. Sadly, just one month after the trailer was released in 2025, he passed away...
He even watched the trailer that was released in 2025 and told me how excited he was for the game to come out this year. Sadly, just one month after the trailer was released in 2025, he passed away...
π27β€4
This media is not supported in your browser
VIEW IN TELEGRAM
π±3π€£3β€1
π List of projects that will be published in this group
(all links are public project sources)
β Confirmed:
β YouTube Morphe (patched by me): https://github.com/MorpheApp/morphe-patches/releases/tag/v1.42.0
β MicroG RE (only new updates): https://github.com/MorpheApp/MicroG-RE/releases/tag/7.1.1
β Metrofuse (only updates): https://github.com/956tris/MetroFuse/releases/tag/7.2
β In progress:
β PlayintegrityFix NEXT: https://github.com/EricInacio01/PlayIntegrityFix-NEXT
NOTE: This list will be updated periodically, with new projects being added and others being removed.
(all links are public project sources)
β Confirmed:
β YouTube Morphe (patched by me): https://github.com/MorpheApp/morphe-patches/releases/tag/v1.42.0
β MicroG RE (only new updates): https://github.com/MorpheApp/MicroG-RE/releases/tag/7.1.1
β Metrofuse (only updates): https://github.com/956tris/MetroFuse/releases/tag/7.2
β In progress:
β PlayintegrityFix NEXT: https://github.com/EricInacio01/PlayIntegrityFix-NEXT
NOTE: This list will be updated periodically, with new projects being added and others being removed.
π₯6β€1
YouTube_Morphe-v21.16.256-patches-v1.44.0.apk
97.7 MB
YouTube Morphe
Changelog: click here.
Version: v1.44.0 (Patches)
Base: 21.16.256
Changelog: click here.
β€1
to everyone who witnessed this, I just have one thing to say:
kkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk
π€£4β€1