xihan123/SignHook
这是一个简单的签名校验通杀模块 observed · 2026-08-28
Health v2 · maintenance only
83/100
- Activity 88
- Release rhythm 77
- Longevity 83
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 37
- age_days: 1170
- days_rel: 73
- days_push: 73
- n_releases_24m: 12
Adoption not part of the score
1354 stars · 83 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
SignHook is an Xposed/LSPosed module for Android that spoofs app signature checks by returning a user-configured fake signature when a host app queries another package's signature. It is commonly used to let modified APKs pass official-app signature verification, e.g. for QQ/WeChat login.
Use cases
- make a modified app pass signature verification for QQ or WeChat login
- spoof package signatures returned to a host app
- fix 'non-official version' errors in repackaged apps
- hook signature queries on Android 9+ with LSPosed
When to choose
- you need a generic signature-spoofing Xposed module on Android 9+
- you use LSPosed or another libxposed-compatible framework
- a modified app fails official login due to signature checks
When to avoid
- you need signature verification bypass without root/Xposed
- you target Android below 9.0
- you need a solution for non-Android platforms
Facets
plugin · maturity active
security developer-tools android-tools security reverse-engineering xposed-module signature-spoofing lsposed app-signature android
1 source
- readme: https://github.com/xihan123/SignHook · fetched 2026-08-28 · d70b395b60e1
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| xihan123/SignHook | main | 83 |
For agents
markdown · JSON · MCP: product_card(name="xihan123/SignHook")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem