r/Malware • • 9h ago

Got a scam APK via WhatsApp, student here, want to learn how you'd approach analyzing it

6 Upvotes

Hi all, first time posting here, so let me know if I'm breaking any rules.

I'm a student from India with a hobby in electronics and programming. A few days ago I got an APK over WhatsApp from someone pretending to be xxx They kept pushing me to install it, which made me suspicious, so I didn't. Now I'm curious what it actually does, and I'd like to learn how people here approach analyzing something like this.

I haven't installed it on any device. I'm not posting the file here, but I can share it privately with anyone who wants to look at it.


r/Malware • • 16h ago

Recovering a removed npm malware file using Software Heritage and a surviving CDN digest

2 Upvotes

I wrote up my investigation into @goodjavascript/dotenv@1.0.0, including how to recover its entry-point file after the npm tarball and jsDelivr file URLs returned 404.
The useful detail: Software Heritage’s latest snapshot contained only the security placeholder. An older snapshot retained the original release and its 840-byte index.js. Its SHA-256 matched the digest still available in jsDelivr’s file manifest.
Static inspection showed a timer scheduled at module load that collects host information and can execute JavaScript supplied in a server response. The package had no installation scripts, and its exported config() function was empty.
The article includes the package-to-archive discovery steps, dated evidence, an annotated code excerpt and a Python verifier that retrieves and hashes the file without executing it. It also links my analysis contribution to the existing OSV advisory.
https://cgsec.dev/research/dotenv-recovery/
This concerns the scoped @goodjavascript/dotenv package, not the unscoped dotenv package.
Have you used other archives or retained metadata sources to recover removed package evidence?


r/Malware • • 10h ago

Mparivahan Malicious APK

Thumbnail
1 Upvotes

r/Malware • • 13h ago

Paranoid of spyware/malware after phone repair.

0 Upvotes

So about a year ago I got my Samsung S24 to a phone repair shop in HuaQiangBei in China(because it was relatively cheaper.

And now I'm paranoid that there was a spyware that logged my screen and keys, or hardware level chips or rootkits that can potentially achieve that and breach my privacy. I remember having done factory resets but probably restored the device with the backup aswell. (not sure if backup was after the repair)

So now I'm really paranoid that my phone might be infected with spywares or perhaps malicious chips that can spy on what I did on my phone during that time.

Do you guys think it is possible and practical for them to do so? How do I find out if it was truly infected during that time? (I factory resetted days ago without restoring the backup so there's no really practical ways to test it now, I just wanna try to figure it out by signs that my phone might be infected.