Forwarded from Gianmarco Gargiulo Mastodon Bridge
#Telegram fork #Nekogram has been caught collecting users' phone numbers with a secret function in the official release binaries.
https://github.com/Nekogram/Nekogram/issues/336
https://github.com/RomashkaTea/nekogram-proof-of-logging
There also was a debug function in #Cherrygram, another fork, immediately removed after the news about Nekogram broke out, although the developer says it was an innocuous unused debug function. I still think it's weird that it sent your phone number to Google Firebase Analytics though.
#Privacy #Security #FOSS
https://github.com/Nekogram/Nekogram/issues/336
https://github.com/RomashkaTea/nekogram-proof-of-logging
There also was a debug function in #Cherrygram, another fork, immediately removed after the news about Nekogram broke out, although the developer says it was an innocuous unused debug function. I still think it's weird that it sent your phone number to Google Firebase Analytics though.
#Privacy #Security #FOSS
GitHub
[Spyware, Malicious code] Malicious Code Injection and User Data Leaking in Release Binaries · Issue #336 · Nekogram/Nekogram
Open-source third-party Telegram client with not many but useful modifications. - [Spyware, Malicious code] Malicious Code Injection and User Data Leaking in Release Binaries · Issue #336 · Nekogram/Nekogram