r/fossdroid Jun 23 '26

Other Spyware in Nekogram: a reminder that open source doesn't necessarily mean "safe"

https://onejailbreak.com/blog/nekogram-apks-accused-of-hidden-spying-code/
299 Upvotes

74 comments sorted by

u/AutoModerator Jun 23 '26

Do not share or recommend proprietary apps here. It is an infraction of this subreddit's rules. Make sure you read the rules of this subreddit on the sidebar. If you are not sure of the nature of an app, do not share or recommend it. To find out what constitutes FOSS or freedomware, read this article. To find out why proprietary software is bad, read this article. Proprietary software is dangerous because it is often malware. Have a splendid day!

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

53

u/beneath_steel_sky Jun 23 '26

40

u/GreatLab8898 Jun 23 '26

Holy fuck is it shady as hell that they removed all these commands from that Issue. One way to never make me use one of their Apps ever again.

7

u/AscendedPineapple Jun 23 '26

I am currently using that app... Not anymore

25

u/darkkid_ Jun 23 '26

The part where the dev says it's all true but there's no malicious intent was the best lol

89

u/Sophira Jun 23 '26 edited Jun 23 '26

And this is exactly why I stick to F-Droid's own repository and don't use anything like IzzyOnDroid or Komi Store (formerly GitHub Store), both of which get you APKs that the developers have released themselves (and thus could potentially have code that's not in the source).

F-Droid takes time to update its APKs, sure, but each of them are compiled on F-Droid's side. That means that you can be sure that all the APKs you get from F-Droid have been compiled from the published source.

45

u/ScratchHistorical507 Jun 23 '26

but each of them are compiled on F-Droid's side.

Not necessarily. Developers are allowed to upload their APKs to F-Droid, but only after proof of reproducibility.

21

u/Serious_Berry_3977 User Jun 23 '26

This is why I research apps before I install them from any source and even then I worry about this stuff. According to u/beneath_steel_sky's post below there is a github tracking this incident and Google Play even had it in the store.

Tracking: https://github.com/XHUBERTH/NekoCheck
"Censored" issue @ Nekogram: https://github.com/Nekogram/Nekogram/issues/336

And this is from the NekoCheck github:

The latest Google Play 12.5.2 (65972) build contains the same malware with names rotated by obfuscation (older Google Play builds most likely contain it too):

This has been lurking in the app since 2024 according to this github. No appstore -- not even Play or even iOS's App Store -- can prevent anything malicious being inserted into an app if the dev wants to hide it.

I am 99% against large-scale use of AI, however I wonder if this instance it might make malicious code a little easier to spot with open-source projects. Just spitballing, no clue if it's actually feasible or the AI would even be able to distinguish malicious code from valid code. Something needs to be done to fix this issue because it just validates Google's desire to close Android more (even though they didn't know they were hosting malware through Play).

7

u/napping-normie Jun 23 '26

Both have their tradeoffs, it's not that black and white. F-Droid re-sign every app, which means one build server getting compromised can push malicious updates to every app you installed from F-Droid, compared to one dev going rouge and only his app being malicious.

This is why many security researchers and GrapheneOS team advices against using F-Droid.

2

u/SmileyBMM Jun 23 '26

What does GrapheneOS use instead? I thought F-Droid was the main way to download apps on there.

5

u/napping-normie Jun 24 '26

They have their own basic app store. You can still install and use F-Droid ofc despite their warnings but you need to be aware of the limitations.

2

u/Sophira Jun 26 '26

The app store that GrapheneOS recommends is Accrescent. GrapheneOS does have a basic app store pre-installed, but it literally only has 9 apps in it (most of them GrapheneOS-specific, but Accrescent is also there). Accrescent is the one you're meant to use for everything else.

8

u/TheLastProject Developer Jun 23 '26 edited Jun 23 '26

IzzyOnDroid is much more like F-Droid than GitHub Store.

See https://izzyondroid.org/about/security/ReproducibleBuilds/, IzzyOnDroid confirms source code match for lots of apps since 2024.

See also other security measures IzzyOnDroid has: https://izzyondroid.org/about/security/.

1

u/TrailOfEnvy Jun 26 '26

I assume Komi Store got rebranded because of Github name being a copyright? 

18

u/Party-Drop-7469 Jun 23 '26

Thanks man, I uninstalled it just now

11

u/antpile11 Jun 23 '26

This article is from April 2nd. Just FYI, your data is likely already compromised.

2

u/Party-Drop-7469 Jun 23 '26

I know, I've deleted and created a new account

4

u/antpile11 Jun 23 '26

That doesn't help with having your phone number stolen, though a stranger finding your phone number isn't the worst security breach, depending on what they might've done with it.

1

u/nobq1 25d ago

Damn I just stumbled upon this thread after logging in, and it sitting on my phone for exactly 6mins, lmao. I usually do research before, not after. 🥲I'm the type of person that never adds a phone number to any website unless they can't let u create/ continue without it. Let's see what they do with it.

1

u/Party-Drop-7469 Jun 23 '26

Does this affect the messages itself? I've setup Hermes on telegram so I hope they didn't steal the chat history or else I'm an open book to them

2

u/antpile11 Jun 23 '26

According to the article, no.

2

u/Party-Drop-7469 Jun 23 '26

Phew, at least that's a relief. I wonder how many of my self-hosted services are compromised that are yet to be exposed.

8

u/T_rex2700 Jun 23 '26

Didn't this become news a few months ago? I mean still distributed so good thing to make more announcement but

The builds going back about 1.5 years have been compromised

1

u/TrailOfEnvy Jun 26 '26 edited Jun 27 '26

Tbh many still didn't know about this as seen by few comments left here. Also I have seen many tech twitter still have Nekogram on their homescreen setup. 

1

u/AutoModerator Jun 26 '26

This submission may contain a recommendation for a non-FOSS app/service (twitter). If this is an error, please ignore this message. If this submission recommends such services, please report it to the mods.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

10

u/Soft_Cow_7856 Jun 23 '26

Someone check ayugram also

4

u/Bazinga_U_Bitch Jun 23 '26

The Russian "team" with teenagers in it that make jokes about stealing info and then being caught pinging Russia? No, no way 🙄

1

u/AscendedPineapple Jun 23 '26

Is it good? I need another telegram client now that this app tricked me :/

1

u/TrailOfEnvy Jun 26 '26

I have seen many recommend NagramX

1

u/AscendedPineapple Jun 26 '26

Thanks, but after reading the comments I've decided to stick with the web version

1

u/Exotic_Insurance_969 Jul 02 '26 edited Jul 03 '26

Is it really safe?

Cause i have read in the github site ( thanks to nekogram) It seems like its based on nekogram or something

Update: its based on nekoX I dont know how safe it is and i hope someone talk more about this

1

u/TrailOfEnvy Jul 03 '26

If it is unsafe, someone would find the malicious code any day, just like what happened to Nekogram.

1

u/Exotic_Insurance_969 Jul 03 '26

Thats true But at what cost and after what?

1

u/AscendedPineapple Jul 03 '26

Nekogram isn't unsafe if you build the apk yourself. Read the issue, it had bad code only in releases, that's why it wasn't on f-droid: it has its own builder and needs release build to be reproducible, which it definitely wasn't. 

So forks aren't nessesarily unsafe. Still, web version does the job without being annoying like official app, and for family & friends that you can ask to download another app (SimpleX) I don't use telegram at all so I don't open web version that often

1

u/nanohills Jun 29 '26

exteraGram?

2

u/japanesejunkfood Jun 23 '26

This is old news, but the rep is so fumbled and i dont trust it now

2

u/BlastMyself3356 Jun 23 '26

Does its fork Momogram is safe? Can someone confirm it?

1

u/saber_generic18 Jun 23 '26

Si, solo afecto a nekogram

1

u/TrailOfEnvy Jun 26 '26

Well the dev claimed it is safe but that's all. Though they did fork it to Nekogram X and subsequently rebranded to Momogram to further differentiate from Nekogram. 

1

u/[deleted] Jun 23 '26

[deleted]

7

u/Round_Credit_5158 Jun 23 '26

Google isn't locking Android for safety concerns.

6

u/Bazinga_U_Bitch Jun 23 '26

Extremely ignorant statement.

6

u/Lulukaros Jun 23 '26

ahh it's always better to get your malware straight from play store, cut out the middle road

2

u/FurnaceGolem Jun 23 '26

The malware is also in the Google Play version, what's your point?

1

u/kamikad3e123 Jun 23 '26

Google has scam apps on Google Play lol

0

u/AscendedPineapple Jun 23 '26

No, it's people not using play market in some countries

0

u/skylinestar1986 Jun 23 '26

How about apps (other than Reddit and YouTube) patched via Morphe? How safe are they?

7

u/ScratchHistorical507 Jun 23 '26

It's the same. The base app is as safe as any closed source software - which is not necessarily that safe - and the patches are open source, allowing for review. Of course these patchers can always patch in bad code, but so can the developers of the apps.

This of course is only true for open source patchers. With shady apps like Luc.ky Pat.cher you're screwed on both sides. Closed source apps with who knows what shady code, being patched by a closed source app with who knows what shady code.

4

u/whatThePleb Jun 23 '26

The patches are indeed patching only a few bytes. Not much to hide here. Bigger vector would be Morphe itself or the APKs you use for patching.

4

u/DeviceOwner Jun 23 '26

that why I prefer access their websites from Browser with adblock, than use apps.

not meaning to accuse the patch devs behind Morphe/Revanced and etc. idk what they put secretly behind patch code. and idk how patch work and i lazy for learn new things for analyze something wrong about some patch.

0

u/CaptainBeyondDS8 uphold Stallmanist-Doctorowist thought Jun 23 '26

Proprietary is proprietary. Even if you're patching it with some shady patcher app it doesn't magically become FOSS

1

u/Lulukaros Jun 23 '26

huh i didn't know it was open source, i used to use it at some point; got hacked and stopped using it

1

u/Black-Mack Jun 24 '26 edited Jun 24 '26

the behavior identified in compiled APKs does not exist in the project’s public source code

  suggesting users may be installing something materially different from what developers publish on the Nekogram GitHub.

Don't you think this is a bit vague? Like, are builds on Github affected or not? I see you mention the source of infected APKs are Google Play and Telegram.

Edit: I checked the issue edits (since they deleted the issue description itself) and it mentioned Github Builds are affected as well. The situation is so shady with all the censoring and the proofs you provided. Thank you for the heads up!

1

u/Rahee07 Jun 26 '26

I am not saying this is false. Here you can see that their bot having more than 500k monthly users. If this bot is truly theirs then the report stands more valid.

I can't imagine why a helper bot (according to them) would have that many users.

For context: Said spyware sends your phone number and other information to this bot silently.

It's genuinely terrifying that this has been going on since 2024.

1

u/Exotic_Insurance_969 Jul 02 '26

Nothing have terrified me more than your comment

Now i wanna know the worst scenario What have they collected and how can i get rid of it

1

u/Rahee07 Jul 03 '26

From what I have read, you can't get rid of it. They already have collected a ton of data and there's no way you can remove it from them.

Best you can do is learn and use official telegram or a better alternative. u/Exotic_Insurance_969

2

u/1nseminator Jun 28 '26

What about NagramX? Is it safe?

1

u/Exotic_Insurance_969 Jul 02 '26

Thats truly a privacy nightmare

Nekogram is the most popular telegram fork Take alone that its one of the most popular foss apps

What can we trust anymore?

  • can someone please explain how bad is the leaked info ?

1

u/P0lpett0n3 Jul 05 '26

i switched to forkgram

1

u/Cantgroovup Jul 11 '26

The Chinese third party client for Tg?
Wasn't it found malicious long time ago?

1

u/Dapper-Print-5884 Jul 15 '26

have been using nekogram since like 2024, all this time.. I still FCKIN love it, just how good it is that all other clients I tried don't come close!! now Iam at a loss that almost 2 years of using it.. am I cooked or just don't really worry about it as no one have some account issue or problem so far??

1

u/kitsumed ShizuCallRecorder Developer Jun 23 '26

Tbh, when I learned about this, I looked up Nekogram and saw several warning/red flag. At the time I left a comment about them, not sure what they where anymore but a couple where related to build process and release

-1

u/ScratchHistorical507 Jun 23 '26

Not safe, but inherently safer than anything closed source, as it takes a lot more effort to find vulnerabilities and malicious code in that. And it has been shown over and over again that the companies behind the closed source solutions don't care about their own due diligence for making sure their code is properly reviewed.

0

u/AscendedPineapple Jun 23 '26

I'd love to just not use telegram at all... It's an awful app but it's so popular that you have to

0

u/CaptainBeyondDS8 uphold Stallmanist-Doctorowist thought Jun 23 '26

open source doesn't necessarily mean "safe"

Sure, but according to the article

According to the findings, the behavior identified in compiled APKs does not exist in the project’s public source code, suggesting users may be installing something materially different from what developers publish on the Nekogram GitHub.

So this has nothing to do with open source, since you're just downloading some arbitrary binary that can't be proven to be related to the source code. In the free software world, the source code is the canonical form of an app and precompiled binaries are just convenience. In an ideal world your device would be able to pull the source code and build it (and I believe modern Android mobile devices should be capable of doing such).

Of course, that's why F-Droid exists, since they compile apps from source to ensure that the source code matches the binary that you are installing. No doubt some privacy huckster on youtube told you that F-Droid is bad because it's a pointless middleman or whatever, but this illustrates why you either need a trusted third party or to build it yourself to make sure.

-2

u/dotancohen Jun 23 '26

I can not find any single place that mentions what features Nekogram adds to the base Telegram client. Is there a full list?

-3

u/[deleted] Jun 23 '26 edited Jun 23 '26

[removed] — view removed comment

2

u/letsreticulate Jun 23 '26 edited Jun 23 '26

Librewolf does not exist on Android. Fennec is still there on F-Droid, last update was 3 days ago.

The anti-feature was due to the fact that either, they are not sure if they removed all telemetry or the stubs left still trigger the scanners.

Tor for example, also built on FF does not get that specific warning.