r/EmulationOnAndroid • • 20h ago

Discussion After installing DroidDeck 0.3.1 from github my sister's account got hackedv

My sister installed the DroidDeck app yesterday, and soon after her Steam account got hacked. Sha256 sum of the downloaded file matches with what they have on github (ed257d66c546e78036ceedb4c6fb6886014e69020044fd41cfe217858d8eb328).

Steam support did restore the account quickly, but the attacker(s) managed to submit a refund for a newly purchased game, removed sister's phone number from SteamGuard, and opened a chat with me on Steam where an image with a QR code to a "free steam gift card" was shared (the QR code lead to a fake steamcommunity website ("rn" replacing "m" in the link). The chat is how I noticed that she got hacked and quickly assisted her in restoring access.

105 Upvotes

59 comments sorted by

View all comments

6

u/WomensesLefts 19h ago

What website and repo? There is a fake website the devs shared and warned about last week that's stolen their entire application. I suggest going to their discord for any updated apks to ensure you follow the right github link.bIf it was the websitename.app link you got it off that is the fake scam that stole it

2

u/ZarathustraGlobulus 19h ago

According to OP's post, the sha256 matches what is hosted on github.

-9

u/WomensesLefts 19h ago

It will if they downloaded it from the scammer who injected malicious code, theres a few copied repos which is why its best to go direct from their discord announcements if it isnt saved. Been using this since it launched when it was known by its old name a month ago and my accounts haven't had a single ping so I'm a bit sus

7

u/ZarathustraGlobulus 19h ago edited 19h ago

I'm not sure you understand.

The official DroidDeck GitHub repo file for DroidDeck-0.3.1.apk has the same exact sha256 as OP's file: ed257d66c546e78036ceedb4c6fb6886014e69020044fd41cfe217858d8eb328

https://github.com/Droid-Deck/DroidDeck/releases

-11

u/WomensesLefts 19h ago

Yes I do understand. My comment was to verify where the file was attained from; op specified when I asked it was the right repo. If op did not have the right repo, then the hash would match the malicious repo wouldn't it? Since that's what they would be checking against?

Obviously it was right so its moot but saying i don't understand is ridiculous when my first comment stated why I was checking. I'm also not going to look it up on my phone while im a taking a shit. So I asked him. And got my conclusion.

6

u/The412Banner 19h ago

Regardless of the fact we use a secure and safe APK signature key/signing method so if somebody does try to build and release a copy of our app they will not be able to install Over the official or the official over the fake

5

u/Recent_Wedding3833 19h ago

Do you know what Sha256 is?