Hacker News new | past | comments | ask | show | jobs | submit login
Vanced was Malware all along
14 points by zeepzeep on March 31, 2022 | hide | past | favorite | 7 comments
Google Play Protect now detects Vanced Manager as malware.

Sure google, seems legit.

https://www.androidpolice.com/google-play-protect-vanced-manager-app/




How could we know that it’s not? Have they published any source code that can be independently built and audited?


I'm curious about this too because virtually every "APK DOWNLOAD" site and non-official APK provider for it embeds malware/adware of some sort. I am wondering how many are actually using a good build and how many are just getting misled by the first result they find.


Searching YouTube Vanced or just Vanced both return the official site as the top result.


I get vanced-manager(com) and apkpure in the top 3 along with the official site.

There is no download link on the official site, and the type of end user that would usually use this does not know what a hash or signature is.


I mean these sorts apps being taken down and easily replaced are ripe for have malware sneakily inserted into the replaced version because there’s suddenly huge demand for the app.


If it were true, it could be a situation like that of The Great Suspender extension.


Does it trigger Virustotal




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: