Ross ROSS = Recommend OSS · open-source software intelligence for agents

davinci1010/pinduoduo_backdoor resource

拼多多apk内嵌提权代码,及动态下发dex分析 observed · 2026-08-28

github.com/davinci1010/pinduoduo_backdoor observed · 2026-08-28

Health v2 · maintenance only

30/100

  • Activity 0
  • Release rhythm 35
  • Longevity 91

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1275
  • days_rel: n/a
  • days_push: 1161
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

5448 stars · 1899 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

A security research repository documenting analysis of privilege-escalation code embedded in the Pinduoduo Android APK, including a VMP-packed dex and dynamically downloaded dex payloads. It reproduces the analysis workflow for Parcel serialization/deserialization mismatch exploits that grant system-level StartAnyWhere capability.

Use cases

  • analyze android apk for hidden privilege escalation code
  • study parcel serialization exploit techniques on android
  • unpack vmp-protected dex files from a chinese app
  • investigate dynamically downloaded dex payloads in mobile apps
  • learn android reverse engineering with a real-world case
  • audit mobile apps for privacy-invading behavior

When to choose

  • you are researching android privilege escalation or parcel deserialization exploits
  • you want a documented real-world case study of app-embedded exploit code
  • you need a starting point for unpacking VMP-shelled dex files

When to avoid

  • you need a maintained tool or library rather than a static analysis write-up
  • you want production-ready or legally cleared code for app auditing
  • you need something with a license or active releases

Facets

learning-resource · maturity maintenance

reverse-engineering security vulnerability-scanning osint security reverse-engineering android-tools privacy mobile-development android-apk-analysis privilege-escalation malware-analysis dex-deobfuscation parcel-exploit security-research pinduoduo android mobile

1 source

Member repositories

RepositoryRoleHealth v2
davinci1010/pinduoduo_backdoormain30

For agents

markdown · JSON · MCP: product_card(name="davinci1010/pinduoduo_backdoor")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem