MBMods: post #826 — TG.ME

MBMods⚠️ Warning! A growing number of WhatsApp mods are quietly stealing your personal data. That includes: - Your phone number - Your contacts' phone numbers - Access to your messages - Data from digital wallet apps (Binance and similar apps) The collected…
How can I tell if my favorite WhatsApp mod contains this malware?

If you're an advanced user, you can inspect the APK using tools such as ApkEditor, ApkTool, or MT Manager.

1. Check the assets folder

If you find any of these files:

- "xprmtofk"
- "ydzntloe"
- "iintbpzx"
- "mieduyzc"
- "pdsydpnb"
- "wqncallq"

then the mod has been injected with this malicious code.

2. Check the DEX files

Open each ".dex" file and look for the following path:

"/androidx/app/xirs/"

If this directory exists, the mod contains the same malicious code.

---

What are these files for?

They only need to be added to any WhatsApp build to make the famous "100% successful account linking" work... 😂

The price? Your data.

---

Does MBWhatsApp contain these files?

No.

I've known about this for months, but I'm only sharing it publicly now so more users are aware of it.

This is also why account linking in MBWhatsApp doesn't work reliably for everyone—including me.

MBWhatsApp is used by my partner, friends, and me, so security and privacy are important.

---

Since when has my data been at risk?

Since the latest code used for account linking was introduced—roughly 3 to 4 months ago, as far as I can tell.

---

Which mods don't contain this malware?

I haven't reviewed every mod, but after checking several, these appear to be clean:

- WhatsApp LiteX
- MBWhatsApp
- LX WhatsApp
- OX WhatsApp

However, if any of these require you to install an "Activator" app, your data is at risk as soon as you install it, (the risk is zero when you install the mod on top of the activator)

Unlike the mods mentioned previously, those already include the malicious code running continuously in the background and collecting data.

---

Can I inspect these files myself?

Only if you're a very advanced user.

The files are heavily protected and intentionally difficult to analyze. I've already unpacked and analyzed them, which is why I'm sharing this information.

---

Why doesn't VirusTotal detect the files in the assets folder?

Because VirusTotal treats them as corrupted or unknown files.

Once they're unpacked and analyzed again, they trigger the detections shown in the previous post.

However, VirusTotal does detect the "/androidx/app/xirs/" directory, which is why mods containing it usually show multiple malware alerts.

---

Which server is my data being sent to?

If you have experience capturing encrypted networks, then check out these links:
- chunkchain. site
- ds_new_fmwa.hasuaki. xyz

---

Did the owner of your favorite mod come out and deny this?


---

This isn't the first time something like this has happened.

The same thing occurred with the HeyWhatsApp mod, which was eventually abandoned after its malicious behavior was exposed.

Read more here:

https://mybroadband.co.za/news/security/452388-fake-whatsapp-warning.html
MyBroadband
Fake WhatsApp warning
WhatsApp security researchers found malware hidden within modified apps.
37❤472😱107👍41👏20🔥13❤‍🔥8🎉7💯7
August 5, 2026 92.1K 108