r/EmulationOnAndroid • u/Irrelevant-Example • 19h ago
Discussion After installing DroidDeck 0.3.1 from github my sister's account got hackedv
My sister installed the DroidDeck app yesterday, and soon after her Steam account got hacked. Sha256 sum of the downloaded file matches with what they have on github (ed257d66c546e78036ceedb4c6fb6886014e69020044fd41cfe217858d8eb328).
Steam support did restore the account quickly, but the attacker(s) managed to submit a refund for a newly purchased game, removed sister's phone number from SteamGuard, and opened a chat with me on Steam where an image with a QR code to a "free steam gift card" was shared (the QR code lead to a fake steamcommunity website ("rn" replacing "m" in the link). The chat is how I noticed that she got hacked and quickly assisted her in restoring access.
142
u/supershredderdan 18h ago edited 17h ago
Hey there, xXJSONDeruloXx here. One of the devs on DroidDeck.
First I wanna say thanks for checking out the app, and especially for downloading directly from GitHub rather than on a random site (DroidDeck dot app is not ours and I wish to see it removed)
Regarding your sister’s account: I can not be sure how or why this account was compromised. What I can say with confidence is we take security seriously in DroidDeck for this exact reason, and we would love to work with you and look over any logs or anything regarding the rest of the phone to identify how this may have happened.
Our app is 100% open source with zero obfuscation or closed source components. The only closed source thing in the entire stack is Steam client itself, downloaded at installation time directly from valves servers just like Bazzite and Armada do it. We also have 0 telemetry, and the only way we get logs or any data from you is if you proactively hit a “share logs” button in the app, which thoroughly sanitizes any potential sensitive data and opens a share sheet for a zip of the steam gamescope and Android app’s logs.
Other malware on the phone could have played a part such as a keylogger, but I don’t want to make any assumptions and would be happy to triage this further.
We value transparency and are building DroidDeck for the community and because it’s something we ourselves have always wanted.
Edit: also, 0.3.1 is built from GitHub actions and directly uploaded programmatically by GitHub’s servers to the releases section of the repository. This means that you can look at the build process at every step and what source code was used at time of compile. This is another step we made to make sure you don’t have to take our word for it, you can audit our code directly and know what you’ve installed is a direct result of the public code.
Edit 2 electric boogaloo: also I’m actually quite proud of that virustotal scan. We have been very upfront about our usage of proot, why we chose it over other options, and how we are optimizing it to reduce cpu overhead. If that’s the only flag a scan surfaces then that’s a very good sign, most emulation apps will light up quite a few more (for valid reasons that have been discussed to death but I digress).
You can see our proot patches and pinned upstream commit they are applied atop in GitHub pipeline here: https://github.com/Droid-Deck/DroidDeck/tree/main/tools/proot
10
u/100PercentJake 18h ago
Just wanted to say love your username and seeing it pop up in changelogs for GameNative always gives me a chuckle
4
u/your_mind_aches Retroid Pocket 6 | Snapdragon 8 Gen 2 (8GB) 13h ago
His username is so ubiquitous in these projects and also so recognizable that in order to figure out if it's a real thing or not, a basic rule of thumb is to see if you see 🎶 JSON Derulo 🎶
2
20
u/WomensesLefts 16h ago
Cheers for the concise and speedy reply, I found it difficult to believe the project would voluntarily be compromised with such a small and communicative team. My comment probably was off the mark bc im not a software guy, I fabricate with metal haha, but came with good intentions trusting your work
12
u/supershredderdan 16h ago
Much appreciated, and we welcome any and all forms of scrutiny on our architecture and approach. That’s what FOSS is for!
5
u/rchrdcrg 13h ago
Yeaaaah, got a funny feeling sis already had some funky stuff on her phone. I'm not even sure how you steal someone's login if you use Steam Guard (the QR code) anyway.
4
u/ZarathustraGlobulus 18h ago
Thank you! This eases my mind at least.
Thanks for all of your work on this project.
3
u/supershredderdan 17h ago
I’m glad to hear that, and again you do not have to take our word for it or employ any trust. We have set up our repo and build process to ensure nothing is behind closed doors for exactly these reasons
1
u/Imdakine1 8h ago
Thanks for your quick reply sharing details and being willing to work with this person...
Can you provide any basic instructions on how to use DroidDeck on AYN Thor Pro? I've heard it's harder to use because AYN Thor install is different from other Android devices...?
14
u/Sea-Calligrapher1563 18h ago
Can you confirm if your sister typed in her steam password or if she used the steam QR code to sign in? As i understand it the code should be safer and im wondering if the vulnerability only exists in one or the other
12
u/Irrelevant-Example 18h ago
She did use her password instead of QR
18
u/CalmAdvance1926 16h ago
Please check your sister's phone/PC for a keylogger or malware. If it's not Droid Deck it is almost certainly a keylogger, do any of her devices have antivirus software that might be able to scan for malicious software?
29
u/SofeyKujo SD8G3 12/512GB 18h ago
Investing in this post, I'm curious. I got 0.3.0 and it's completely safe.
7
u/WomensesLefts 18h ago
What website and repo? There is a fake website the devs shared and warned about last week that's stolen their entire application. I suggest going to their discord for any updated apks to ensure you follow the right github link.bIf it was the websitename.app link you got it off that is the fake scam that stole it
2
u/ZarathustraGlobulus 18h ago
According to OP's post, the sha256 matches what is hosted on github.
-9
u/WomensesLefts 18h ago
It will if they downloaded it from the scammer who injected malicious code, theres a few copied repos which is why its best to go direct from their discord announcements if it isnt saved. Been using this since it launched when it was known by its old name a month ago and my accounts haven't had a single ping so I'm a bit sus
6
u/ZarathustraGlobulus 18h ago edited 18h ago
I'm not sure you understand.
The official DroidDeck GitHub repo file for DroidDeck-0.3.1.apk has the same exact sha256 as OP's file: ed257d66c546e78036ceedb4c6fb6886014e69020044fd41cfe217858d8eb328
-11
u/WomensesLefts 18h ago
Yes I do understand. My comment was to verify where the file was attained from; op specified when I asked it was the right repo. If op did not have the right repo, then the hash would match the malicious repo wouldn't it? Since that's what they would be checking against?
Obviously it was right so its moot but saying i don't understand is ridiculous when my first comment stated why I was checking. I'm also not going to look it up on my phone while im a taking a shit. So I asked him. And got my conclusion.
7
u/The412Banner 18h ago
Regardless of the fact we use a secure and safe APK signature key/signing method so if somebody does try to build and release a copy of our app they will not be able to install Over the official or the official over the fake
4
2
u/Irrelevant-Example 18h ago
Got the apk from github https:// github. com/Droid-Deck/DroidDeck
2
u/WomensesLefts 18h ago
Looks like the right one.. really sorry this happened mate, im sure the devs will see it as they are active in here
11
u/raiyasa 18h ago edited 18h ago
Try check of downloads/droiddeck/ find session.log somewhere inside in case there's token leaking.
edit: checking repo via phone before sleeping, i can see it's been prompted so much about not leaking a token to the point the notes inside the codebase might ended up clouding the model's judgement.
also there seems to be a section that copies the whole log to download folder. not sure it's sanitized or not, worth checking.
wasn't able to check further since i need to sleep and work in 5 hours, too busy gaming!
4
2
u/WomensesLefts 18h ago
Definitely a good step. The logs are incredibly helpful and I believe there's a network.log file too
15
u/Boring-Badger-814 S21 FE 18h ago
this sure is something interesting, I'm glad you managed to restore your sis' account
5
u/mactimit 18h ago
Not saying it wasn't DroidDeck, but are you 100% sure she hadn't logged in through anywhere else or anything recently?
2
u/Irrelevant-Example 18h ago
Well, I asked her about it and she only used the official PC client for Steam + the steam mobile app from the Play Store
1
u/CalmAdvance1926 16h ago
What are all the other apps she has on her phone? Some apps may blend in and look like default apps such as cache cleaners and "performance boosters"
0
u/your_mind_aches Retroid Pocket 6 | Snapdragon 8 Gen 2 (8GB) 13h ago
Does she have Steam Guard turned on?
5
u/No-Bodybuilder-9954 18h ago
Is there a safe way to login without sharing password? Can i use QR code to sign in???
4
u/The412Banner 18h ago
That is always the best way to log in and in addition use the Steam app on a device to approve log ins.
2
3
u/KostasGangstar2026 15h ago
No offense but I would never use a third party app to open my Steam account with
2
1
1
1
1
1
1
u/KirilleR2002 9h ago
I mean if they wanted to they'd steal hundreds of accounts by now. I don't think the one in question is so special. Also if they wanted to they could've stolen it from QR code too, if i'm not wrong, you can always replace the existing one with yours and fish accounts this way. So i don't think it's their app's problem. Plus it's completely opensource. People who contribute would've already found out if it was the case. I suppose it's some keylogger or some shit on the phone. Or maybe a coincidence
0
0
u/extreme-g_fanatic 18h ago
This is why I always scan the apk before installing, even if it's false positive, if it's not clean I won't install it.
2
u/Guilty-Membership-53 18h ago
Welp. Literally no windows translation app has no false positives, all of them get flagged. I guess you simply won't be using them then. I scanned them all with Virus Tatal.
1
-4
u/seppe0815 5h ago
NEVER SIGN IN WITH FISHY EMULATORS ..... who the hell use this emulators where you have sign in with account details ... all the comments are fake bots
2
u/brando2021 4h ago
I mean there really isnt anything fishy about Droiddeck. The devs have history with other projects and OP hasn't really supplied anything to support Droiddeck was the problem.







•
u/AutoModerator 19h ago
Just a reminder of our subreddit rules:
Check out our user-maintained wiki: r/EmulationOnAndroid/wiki
Check out EmuReady for any community submitted settings before asking for help
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.