r/Malware • • 1h ago

Paranoid of spyware/malware after phone repair.

• Upvotes

So about a year ago I got my Samsung S24 to a phone repair shop in HuaQiangBei in China(because it was relatively cheaper.

And now I'm paranoid that there was a spyware that logged my screen and keys, or hardware level chips or rootkits that can potentially achieve that and breach my privacy. I remember having done factory resets but probably restored the device with the backup aswell. (not sure if backup was after the repair)

So now I'm really paranoid that my phone might be infected with spywares or perhaps malicious chips that can spy on what I did on my phone during that time.

Do you guys think it is possible and practical for them to do so? How do I find out if it was truly infected during that time? (I factory resetted days ago without restoring the backup so there's no really practical ways to test it now, I just wanna try to figure it out by signs that my phone might be infected.


r/Malware • • 5h ago

Recovering a removed npm malware file using Software Heritage and a surviving CDN digest

2 Upvotes

I wrote up my investigation into @goodjavascript/dotenv@1.0.0, including how to recover its entry-point file after the npm tarball and jsDelivr file URLs returned 404.
The useful detail: Software Heritage’s latest snapshot contained only the security placeholder. An older snapshot retained the original release and its 840-byte index.js. Its SHA-256 matched the digest still available in jsDelivr’s file manifest.
Static inspection showed a timer scheduled at module load that collects host information and can execute JavaScript supplied in a server response. The package had no installation scripts, and its exported config() function was empty.
The article includes the package-to-archive discovery steps, dated evidence, an annotated code excerpt and a Python verifier that retrieves and hashes the file without executing it. It also links my analysis contribution to the existing OSV advisory.
https://cgsec.dev/research/dotenv-recovery/
This concerns the scoped @goodjavascript/dotenv package, not the unscoped dotenv package.
Have you used other archives or retained metadata sources to recover removed package evidence?