Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

tateu

macrumors 6502
Original poster
Jan 27, 2012
358
1
Another peice of possible malware has been found, and this one comes from a package on a default repo: BigBoss.

http://www.reddit.com/r/jailbreak/comments/23mu31/psa_do_not_update_screenshotalbum/
http://www.reddit.com/r/jailbreak/comments/23mo1h/appsafedylib_stucked_my_phone/

The latest version 1.2 of ScreenShotAlbum has malicious code that downloads and installs AppSafe.dylib from hxxp://www.gaoqing.mobi/dylib/api/checkupdate.php. According to the above reddit post, AppSafe.dylib appears to be
IAMA_LION_AMA said:
a malicious program which was made with the intent to steal ad revenue from other developers by replacing the ad IDs in their apps. It does not steal your data, it only modifies (Google's?) advertisement framework.

I would also recommend staying away from that developers other packages, until more is known about them: iSnapShot and SnapToShare.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.