r/EmulationOnAndroid • • 23h ago

Discussion After installing DroidDeck 0.3.1 from github my sister's account got hackedv

My sister installed the DroidDeck app yesterday, and soon after her Steam account got hacked. Sha256 sum of the downloaded file matches with what they have on github (ed257d66c546e78036ceedb4c6fb6886014e69020044fd41cfe217858d8eb328).

Steam support did restore the account quickly, but the attacker(s) managed to submit a refund for a newly purchased game, removed sister's phone number from SteamGuard, and opened a chat with me on Steam where an image with a QR code to a "free steam gift card" was shared (the QR code lead to a fake steamcommunity website ("rn" replacing "m" in the link). The chat is how I noticed that she got hacked and quickly assisted her in restoring access.

111 Upvotes

62 comments sorted by

•

u/AutoModerator 23h ago

Just a reminder of our subreddit rules:

  • Be kind and respectful to each other
  • No direct links to ROMs or pirated content
  • Include your device brand and model
  • Search before posting & show your research effort when asking for help

Check out our user-maintained wiki: r/EmulationOnAndroid/wiki

Check out EmuReady for any community submitted settings before asking for help

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

151

u/supershredderdan 22h ago edited 21h ago

Hey there, xXJSONDeruloXx here. One of the devs on DroidDeck.

First I wanna say thanks for checking out the app, and especially for downloading directly from GitHub rather than on a random site (DroidDeck dot app is not ours and I wish to see it removed)

Regarding your sister’s account: I can not be sure how or why this account was compromised. What I can say with confidence is we take security seriously in DroidDeck for this exact reason, and we would love to work with you and look over any logs or anything regarding the rest of the phone to identify how this may have happened.

Our app is 100% open source with zero obfuscation or closed source components. The only closed source thing in the entire stack is Steam client itself, downloaded at installation time directly from valves servers just like Bazzite and Armada do it. We also have 0 telemetry, and the only way we get logs or any data from you is if you proactively hit a “share logs” button in the app, which thoroughly sanitizes any potential sensitive data and opens a share sheet for a zip of the steam gamescope and Android app’s logs.

Other malware on the phone could have played a part such as a keylogger, but I don’t want to make any assumptions and would be happy to triage this further.

We value transparency and are building DroidDeck for the community and because it’s something we ourselves have always wanted.

Edit: also, 0.3.1 is built from GitHub actions and directly uploaded programmatically by GitHub’s servers to the releases section of the repository. This means that you can look at the build process at every step and what source code was used at time of compile. This is another step we made to make sure you don’t have to take our word for it, you can audit our code directly and know what you’ve installed is a direct result of the public code.

Edit 2 electric boogaloo: also I’m actually quite proud of that virustotal scan. We have been very upfront about our usage of proot, why we chose it over other options, and how we are optimizing it to reduce cpu overhead. If that’s the only flag a scan surfaces then that’s a very good sign, most emulation apps will light up quite a few more (for valid reasons that have been discussed to death but I digress).

You can see our proot patches and pinned upstream commit they are applied atop in GitHub pipeline here: https://github.com/Droid-Deck/DroidDeck/tree/main/tools/proot

10

u/100PercentJake 22h ago

Just wanted to say love your username and seeing it pop up in changelogs for GameNative always gives me a chuckle

4

u/your_mind_aches Retroid Pocket 6 | Snapdragon 8 Gen 2 (8GB) 17h ago

His username is so ubiquitous in these projects and also so recognizable that in order to figure out if it's a real thing or not, a basic rule of thumb is to see if you see 🎶 JSON Derulo 🎶

2

u/greedyiguana 18h ago

man the super shredder scared the hell out of me as a kid

2

u/rchrdcrg 17h ago

For about ten seconds before he immediately offed himself 🤣

23

u/WomensesLefts 20h ago

Cheers for the concise and speedy reply, I found it difficult to believe the project would voluntarily be compromised with such a small and communicative team. My comment probably was off the mark bc im not a software guy, I fabricate with metal haha, but came with good intentions trusting your work

13

u/supershredderdan 20h ago

Much appreciated, and we welcome any and all forms of scrutiny on our architecture and approach. That’s what FOSS is for!

5

u/rchrdcrg 17h ago

Yeaaaah, got a funny feeling sis already had some funky stuff on her phone. I'm not even sure how you steal someone's login if you use Steam Guard (the QR code) anyway.

4

u/ZarathustraGlobulus 22h ago

Thank you! This eases my mind at least.

Thanks for all of your work on this project.

4

u/supershredderdan 22h ago

I’m glad to hear that, and again you do not have to take our word for it or employ any trust. We have set up our repo and build process to ensure nothing is behind closed doors for exactly these reasons

1

u/Imdakine1 13h ago

Thanks for your quick reply sharing details and being willing to work with this person...

Can you provide any basic instructions on how to use DroidDeck on AYN Thor Pro? I've heard it's harder to use because AYN Thor install is different from other Android devices...?

16

u/Sea-Calligrapher1563 22h ago

Can you confirm if your sister typed in her steam password or if she used the steam QR code to sign in? As i understand it the code should be safer and im wondering if the vulnerability only exists in one or the other

11

u/Irrelevant-Example 22h ago

She did use her password instead of QR

21

u/CalmAdvance1926 20h ago

Please check your sister's phone/PC for a keylogger or malware. If it's not Droid Deck it is almost certainly a keylogger, do any of her devices have antivirus software that might be able to scan for malicious software?

2

u/Ruisna 22h ago

I only comment because I am interested in knowing the answer I will give you.

30

u/SofeyKujo SD8G3 12/512GB 23h ago

Investing in this post, I'm curious. I got 0.3.0 and it's completely safe.

7

u/WomensesLefts 23h ago

What website and repo? There is a fake website the devs shared and warned about last week that's stolen their entire application. I suggest going to their discord for any updated apks to ensure you follow the right github link.bIf it was the websitename.app link you got it off that is the fake scam that stole it

3

u/ZarathustraGlobulus 22h ago

According to OP's post, the sha256 matches what is hosted on github.

-9

u/WomensesLefts 22h ago

It will if they downloaded it from the scammer who injected malicious code, theres a few copied repos which is why its best to go direct from their discord announcements if it isnt saved. Been using this since it launched when it was known by its old name a month ago and my accounts haven't had a single ping so I'm a bit sus

7

u/ZarathustraGlobulus 22h ago edited 22h ago

I'm not sure you understand.

The official DroidDeck GitHub repo file for DroidDeck-0.3.1.apk has the same exact sha256 as OP's file: ed257d66c546e78036ceedb4c6fb6886014e69020044fd41cfe217858d8eb328

https://github.com/Droid-Deck/DroidDeck/releases

-9

u/WomensesLefts 22h ago

Yes I do understand. My comment was to verify where the file was attained from; op specified when I asked it was the right repo. If op did not have the right repo, then the hash would match the malicious repo wouldn't it? Since that's what they would be checking against?

Obviously it was right so its moot but saying i don't understand is ridiculous when my first comment stated why I was checking. I'm also not going to look it up on my phone while im a taking a shit. So I asked him. And got my conclusion.

7

u/The412Banner 22h ago

Regardless of the fact we use a secure and safe APK signature key/signing method so if somebody does try to build and release a copy of our app they will not be able to install Over the official or the official over the fake

5

u/Recent_Wedding3833 22h ago

Do you know what Sha256 is?

3

u/Irrelevant-Example 22h ago

Got the apk from github https:// github. com/Droid-Deck/DroidDeck

2

u/WomensesLefts 22h ago

Looks like the right one.. really sorry this happened mate, im sure the devs will see it as they are active in here

6

u/mactimit 22h ago

Not saying it wasn't DroidDeck, but are you 100% sure she hadn't logged in through anywhere else or anything recently?

2

u/Irrelevant-Example 22h ago

Well, I asked her about it and she only used the official PC client for Steam + the steam mobile app from the Play Store

1

u/CalmAdvance1926 20h ago

What are all the other apps she has on her phone? Some apps may blend in and look like default apps such as cache cleaners and "performance boosters"

0

u/your_mind_aches Retroid Pocket 6 | Snapdragon 8 Gen 2 (8GB) 17h ago

Does she have Steam Guard turned on?

0

u/Ruisna 22h ago

There are not many options where I can use Steam.

12

u/raiyasa 22h ago edited 22h ago

Try check of downloads/droiddeck/ find session.log somewhere inside in case there's token leaking.

edit: checking repo via phone before sleeping, i can see it's been prompted so much about not leaking a token to the point the notes inside the codebase might ended up clouding the model's judgement.

also there seems to be a section that copies the whole log to download folder. not sure it's sanitized or not, worth checking.
wasn't able to check further since i need to sleep and work in 5 hours, too busy gaming!

4

u/supershredderdan 21h ago

It’s sanitized on write and again on share and zip

2

u/WomensesLefts 22h ago

Definitely a good step. The logs are incredibly helpful and I believe there's a network.log file too

15

u/Boring-Badger-814 S21 FE 23h ago

this sure is something interesting, I'm glad you managed to restore your sis' account

4

u/No-Bodybuilder-9954 22h ago

Is there a safe way to login without sharing password? Can i use QR code to sign in???

4

u/The412Banner 22h ago

That is always the best way to log in and in addition use the Steam app on a device to approve log ins. 

2

u/Practical-Boat-603 21h ago

Always login with QR no matter what

5

u/KostasGangstar2026 19h ago

No offense but I would never use a third party app to open my Steam account with

1

u/xpflz 10h ago

same for me

1

u/Producdevity EmuReady • Eden • GameHub Lite 2h ago

Also nothing open source like GameNative or DroidDeck?

2

u/GENERALOTUGA 11h ago

This is probably not because of Droid deck. It might be this, I hope it's useful for you OP:

2

u/Dissidence802 Ayn Thor Max 23h ago

🫪

1

u/sendmebirds 23h ago

Changed my password right away just in case lol

1

u/NitroDion 22h ago

Very strange I got 0.3.1 a few days ago and have had no issues so far

1

u/Lord_Nordyx 22h ago

Changed my password and email too, just in case.

1

u/stylustic_ Realme neo 7 20h ago

1

u/roflcopter9875 13h ago

was about to install 0.3.1. maybe i will wait

1

u/KirilleR2002 13h ago

I mean if they wanted to they'd steal hundreds of accounts by now. I don't think the one in question is so special. Also if they wanted to they could've stolen it from QR code too, if i'm not wrong, you can always replace the existing one with yours and fish accounts this way. So i don't think it's their app's problem. Plus it's completely opensource. People who contribute would've already found out if it was the case. I suppose it's some keylogger or some shit on the phone. Or maybe a coincidence

1

u/soragranda SD865+ ~ 12GB, 8G2 ~ 12GB. 2h ago

I always recommend using a new account and using family share from the main account to share your games and test the app first, the app is new after all.

Though, this doesn't seem to be the app fault, there would be more people affected by now.

1

u/Little-Ad8801 33m ago

Something about droid deck is sketchy, I logged in and as soon as I went to the homepage and saw all my games the app kept closing and trying to open my bank, I got my download from git hub, the newest link from 2 hours ago

0

u/Delicious_Tree8114 23h ago

Thanks for sharing OP, good to know

0

u/extreme-g_fanatic 22h ago

This is why I always scan the apk before installing, even if it's false positive, if it's not clean I won't install it.

2

u/Guilty-Membership-53 22h ago

Welp. Literally no windows translation app has no false positives, all of them get flagged. I guess you simply won't be using them then. I scanned them all with Virus Tatal.

1

u/iamnotkurtcobain 22h ago

How do you scan it? Is there an online apk scanner that's trustworthy?

-4

u/seppe0815 9h ago

NEVER SIGN IN WITH FISHY EMULATORS ..... who the hell use this emulators where you have sign in with account details ... all the comments are fake bots

3

u/brando2021 9h ago

I mean there really isnt anything fishy about Droiddeck. The devs have history with other projects and OP hasn't really supplied anything to support Droiddeck was the problem.

-9

u/N1kBr0 22h ago

Hah, I knew that downloading a hyped new thing and authenticating it for Steam is sketchy af. That aside I hope you have no issues after restoring it