# davinci1010/pinduoduo_backdoor

拼多多apk内嵌提权代码，及动态下发dex分析

Repository: https://github.com/davinci1010/pinduoduo_backdoor
Canonical: https://ross.abutalabs.com/products/pinduoduo_backdoor
License Family: other
Topics: pdd
Last push: 2023-06-29T08:10:29+00:00

## Health v2 (maintenance only)
Score: 30/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 91
- inputs: {"age_days": 1275, "days_push": 1161, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 5448, forks 1899 (observed 2026-08-28T04:09:18.633750+00:00)

## What it is
A security research repository documenting analysis of privilege-escalation code embedded in the Pinduoduo Android APK, including a VMP-packed dex and dynamically downloaded dex payloads. It reproduces the analysis workflow for Parcel serialization/deserialization mismatch exploits that grant system-level StartAnyWhere capability.

## Use cases
- analyze android apk for hidden privilege escalation code
- study parcel serialization exploit techniques on android
- unpack vmp-protected dex files from a chinese app
- investigate dynamically downloaded dex payloads in mobile apps
- learn android reverse engineering with a real-world case
- audit mobile apps for privacy-invading behavior

## When to choose
- you are researching android privilege escalation or parcel deserialization exploits
- you want a documented real-world case study of app-embedded exploit code
- you need a starting point for unpacking VMP-shelled dex files

## When to avoid
- you need a maintained tool or library rather than a static analysis write-up
- you want production-ready or legally cleared code for app auditing
- you need something with a license or active releases

## Facets
- artifact type: learning-resource
- maturity: maintenance
- function: reverse-engineering, security, vulnerability-scanning, osint
- domain: security, reverse-engineering, android-tools, privacy, mobile-development
- platform: -
- tags: android-apk-analysis, privilege-escalation, malware-analysis, dex-deobfuscation, parcel-exploit, security-research, pinduoduo, android, mobile

## Member repositories
- davinci1010/pinduoduo_backdoor (main) score 30

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:18.633750+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:56:50.399500+00:00, confidence not recorded.
  - readme: https://github.com/davinci1010/pinduoduo_backdoor (fetched 2026-08-28T04:09:18.633750+00:00, sha ab445b68842d)
- Data as of 2026-08-30T08:39:29.467469+00:00.
