

This isn't a free, but...
BREAKING: Nekogram is secretly sending your phone numbers to the developer
The backdoor is hidden in the
You must be registered for see links
file, which differs from the template uploaded to the repository. The obfuscated code sends data as an inline request to the @nekonotificationbot, leaving no trace.
More info about the backdoor:
You must be registered for see links
(locked by Nekogram devs)To validate this, we made a PoC: an LSPosed module that replaces the bot ID and username to ours so all requests are going to it. That way, we confirmed that the phone numbers are being collected. Every. Login.
The PoC is available here:
You must be registered for see links
What should you do?
1. Report the app on Play Store:
You must be registered for see links
2. Report the repository on GitHub:
You must be registered for see links
3. Delete the app and stop using unofficial Telegram clients
in few minutes imma gonna delete the fork from the apks subforum if its possible

