VirusTotal • MYTH APK

Proof, not promises.

64/64 — fully clean.

Every hash, permission, and byte for who check data, not headlines. All 64 engines clean. No flags, no malware.

64/64 clean0 malware

Summary

64/64 clean. Zero detections for trojan, ransomware, spyware, malware.

64
Clean
0
Flags
64
Engines

AI said 'legal spyware' — here's what's actually true

That viral AI breakdown reads normal Expo app behavior as if it were spyware. Every line below is normal for 100M+ React Native apps.

🚩 "Obfuscated code = hiding trackers"
No. That's Hermes bytecode + minify. Every React Native app ships obfuscated to be smaller/faster. You can still decompile with apktool — nothing hidden. Real hiding would be encrypted native payloads, not JS minify.
📋 "Reads your clipboard"
No. T1414 Clipboard Data fires because expo-clipboard is bundled — even if you never call it. MYTH only reads clipboard when you paste a character image. No background polling.
📍 "Tracks GPS / location"
No. No ACCESS_FINE_LOCATION or ACCESS_COARSE_LOCATION in permissions. The "checks-gps" tag is a heuristic because a dependency imported the word "location". Uninstall location code = tag still fires.
🔊 "Audio capture / telephony spy"
RECORD_AUDIO + FOREGROUND_SERVICE_MICROPHONE exist only for voice messages/calls — you tap mic, then we record. No background audio. "Telephony" is just Expo.Audio checking if a call is active to duck music.
🔔 "Forces itself to run at boot forever"
That was RECEIVE_BOOT_COMPLETED + WAKE_LOCK — added by old build, already removed for next APK. Leftovers only kept notifications working after reboot. Next build drops them. No "forever background".
🎯 "Aggressive ad trackers (AD_ID)"
AD_ID came from Firebase + Expo, not us tracking you to sell. It's for "watch ad to get 30 messages" attribution. Already blocked for next build. No tracking without your tap on "watch ad".
🏛️ "Release certificate" — verified
Current APK ships with a proper release keystore (eas credentials), valid 2026–2054. Not a debug cert, not a backdoor — see Certificate section below.
📄 "Legal trap / admins read everything"
Same as Character AI / Discord / Telegram: messages must be read to generate a reply. Difference: we show it and let you export or delete everything (Settings → Data & Storage, ~60 tables, one tap). No resale. No contacts/SMS harvesting — ever.

Bottom line: 64/64 clean, 0 malware, 0 IDS hits. Verify yourself with the hashes below.

Privacy & legal — what that AI got right, and what it stretched

Honest answers to the 'no privacy / legal trap' claims. No spin — just what the Terms actually say and why.

🔀 "10-15 AI companies see your chats" — stretched, and we keep the routing private
Truth: Your chat is sent to our AI gateway (OpenAI-compatible) which routes to a vetted model provider to generate the reply. The exact provider may rotate for uptime — like how every major app has a fallback — so we don't publish a single name. Voice is separate: Groq for transcription and Vapi/ElevenLabs for calls, only when you use voice. That's it. Listed generically in Terms §9 as "AI provider via gateway".
Do they train on it? We don't train on your chats and we don't resell them. Because the gateway may use different model providers, we can't centrally guarantee every provider's future training policy — so we say so honestly instead of pretending we control it. That's why the AI calls it "no central control". You can still object to training via support (Terms §8) and we honor it where technically feasible.
🔓 "No end-to-end encryption — plain text on servers" — true, and true for every AI chat app
True: Messages are encrypted at rest (AES-256-GCM) in our DB (Convex), but our servers do decrypt to generate a reply — otherwise the AI can't read it. Character AI, Replika, Discord, Telegram all do the same. If it were E2E, the AI couldn't reply.
We state it plainly in Terms §8: "you should have no expectation of privacy from the platform" — meaning our servers, not the public. Manual human review only on reported violations or legal requirement, not browsing. And you can export or wipe everything in one tap: Settings → Data & Storage → Delete (wipes ~60 tables + Clerk). No ghost recovery.
⚖️ "Liability capped at ₹1,000 / creators take 100% risk" — true, and standard for a free app
₹1,000 cap (Terms §71): Because MYTH is free — you pay ₹0 — a free service can't carry unlimited liability for emotional harm without going bankrupt. Paid apps do the same. The cap is whichever is lower: what you paid in last 3 months or ₹1,000. If subscription comes later, your paid amount becomes the cap.
Creator 100% risk (Creator Terms §§1-3): If you publish a public character that copies a real person or copyrighted IP (e.g., "Naruto", a real influencer), you are liable — like a YouTuber who uploads a movie. MYTH has to hand your verified name/address to law enforcement on a valid subpoena/DMCA — that's why Creator verification asks for ID. Private characters (visibility off) don't need this; public = publishing.
Read it verbatim: Terms §6-11 · Creator Terms · Privacy §8

We could have hidden this in legalese. We put it in plain text and on this page so you can decide *before* you chat — that's the opposite of a trap.

Basic properties

SHA256 for the current MYTH APK. Copy it and search on VirusTotal.

SHA-256c8a8fbab8a2668e9223bde4df510f0c04c31b94c82e172988e9e5cb89b42f08e

History

Submission and content timestamps.

First Submission2026-10-04 02:33:30 UTC
Last Submission2026-10-04 02:33:30 UTC
Last Analysis2026-10-04 02:33:30 UTC
Earliest Contents Modification1981-01-01 01:01:02
Latest Contents Modification1981-01-01 01:01:02

Android info

Package identity and SDK targets.

Android TypeAPK
Package Namesounds.like.a.myth
Main Activitysounds.like.a.myth.MainActivity
Internal Version48
Displayed Version1.0.3
Minimum SDK24 (Android 7.0)
Target SDK36 (Android 14+)

Certificate

Release cert, valid 2026–2054.

Subject / IssuerC:US
Serial16fcb5d457f907a
Thumbprint5267fbf78aca4dee89919fcb24b4385e76ff6888
Valid From2026-09-28 16:24:51
Valid To2054-02-13 16:24:51

Permissions (42)

Only mic + camera + media/storage + notifications are user-facing. The rest are launcher badges, ads, and system helpers. No SMS, no call logs, no contacts harvest.

android.permission.RECORD_AUDIOandroid.permission.CAMERAandroid.permission.READ_MEDIA_IMAGES / VIDEO / AUDIOandroid.permission.READ_MEDIA_VISUAL_USER_SELECTEDandroid.permission.READ_EXTERNAL_STORAGE / WRITE_EXTERNAL_STORAGEandroid.permission.POST_NOTIFICATIONSandroid.permission.FOREGROUND_SERVICE + _MICROPHONE/_CAMERA/_MEDIA_PROJECTIONandroid.permission.SYSTEM_ALERT_WINDOWandroid.permission.SCHEDULE_EXACT_ALARM / RECEIVE_BOOT_COMPLETED / WAKE_LOCK / VIBRATEandroid.permission.INTERNET / ACCESS_NETWORK_STATE / ACCESS_ADSERVICES_*android.permission.USE_BIOMETRIC / USE_FINGERPRINTandroid.permission.MODIFY_AUDIO_SETTINGS / BLUETOOTHandroid.permission.ACTIVITY_RECOGNITIONcom.google.android.gms.permission.AD_ID + BIND_GET_INSTALL_REFERRER_SERVICElauncher badge perms (huawei/oppo/htc/sony/sec/…UPDATE_BADGE)

Full list of 42 in VirusTotal report — grouped above for readability. Ask us if a permission looks odd.

Components

Activities, services, receivers, providers, and intent filters declared in the APK.

Activities (5)
am.a.myth.MainActivity, PreviewActivity, HiddenActivity ×2, InstrumentationActivityInvoker
Services (5)
CredentialProviderMetadataHolder, MultiInstanceInvalidationService, SystemAlarmService, SystemJobService, SystemForegroundService
Receivers (5)
ProfileInstallReceiver, ConstraintProxy ×4 (BatteryCharging/NotLow, NetworkState, StorageNotLow)
Providers (4)
InitializationProvider, CropFileProvider, SharedSessionSyncProvider, MobileAdsInitProvider, FirebaseInitProvider
Intent filters
VIEW/MAIN/DEVICE_STORAGE_LOW + MESSAGING_EVENT + MODULE_DEPENDENCIES · categories DEFAULT/BROWSABLE/LAUNCHER
Interesting strings
http://ns.adobe.com/xap/1.0/ · https://www.example.com

Contents metadata

2,413 files inside. Mostly SO/ELF, XML, PNG, DEX, properties. Uncompressed 202.92 MB.

Contained Files2,413
Uncompressed Size202.92 MB
By TypeJAVA BYTECODE 1, JSON 2, PNG 18, XML 21, ELF 104, UNKNOWN 854, SO 104, DEX 8, etc.
By ExtensionGZ, PROFM, PEM, PROF, MANIFEST, CONFIG, BIN, BUNDLE, SO 104, PNG 16, XML 21, PROPERTIES 34, VERSION 110, TXT 133, ...
Warnings
Contains one or more Linux executables. (Expected — native libs for image/AVIF/gif, hermes, c++_shared, fbjni, etc.)

Bundled files (sample)

Every file inside scored 0 detections. Sample 10 of 100+ shown — all 0/60-63 clean.

META-INF/com/android/build/gradle/app-metadata.properties57 B · 411dcc6d…f3d · 0/60
META-INF/version-control-info.textproto46 B · 38d377af…928 · 0/61
lib/arm64-v8a/libandroidx.graphics.path.so9.86 KB · 41e9a793…fb6 · 0/60
lib/arm64-v8a/libanimation-decoder-gif.so268.91 KB · 1a36facc…933 · 0/62
lib/arm64-v8a/libavif_android.so— · — · 0/62
lib/arm64-v8a/libc++_shared.so1.23 MB · 3e852764…214 · 0/53
lib/arm64-v8a/libfbjni.so172.85 KB · a9e35ba5…b22 · 0/63
lib/arm64-v8a/libgifimage.so311.52 KB · 9f605249…15c · 0/62
lib/arm64-v8a/libhermestooling.so138.12 KB · fcab3faa…465 · 0/57

Full 100+ list in VirusTotal → Bundled Files tab. All 0 detections.

Dropped files

2 files created at runtime (shared_prefs XML), both 0/61 clean.

stream_permission.xml65 B · SHA256 3325d2a819fdd8062c2cdc48a09b995c9b012915bcdf88b1cf9742a7f057c793 · 0/61
Paths: /data/user/0/am.a.myth/shared_prefs/expo.modules.*.xml

Network

10 IPs contacted (Google infra 15169/13335), 7 JA3 digests, 9 memory domains/URLs. All low detections.

104.18.14.131 — 0/89 · AS13335104.21.64.137 — 0/89 · AS13335142.251.155.119 — 0/89 · AS15169 US172.217.113.4 — 0/89 · AS15169 US172.217.114.4 — 0/89 · AS15169 US172.217.115.4 — 0/89 · AS15169 US172.217.214.100 — 0/89 · AS15169 US172.64.153.110 — 1/89 · AS13335173.194.64.100 — 0/89 · AS15169 US173.194.195.156 — 0/89 · AS15169 US
Memory pattern domains
android.googlesource.com, fontawesome.com, goo.gle, ktor.io, reactnative.dev, schemas.android.com, scripts.sil.org, software.sil.org, www.apache.org, www.bouncycastle.org
TLS SNI
infinitedata-pa.googleapis.com
57f15b78…c3e669659b6d…ab13893d2529…b01c8f35687f…6c09b02ebd3…dc8aa50c12a…79d5f79b6bad…56b

Behavior

13 MITRE techniques (all INFO), no IDS/Sigma hits. Tags: checks-gps, obfuscated, reflection, telephony.

0
Detections
13 INFO
Mitre
0
IDS / Sigma
T1406 Obfuscated Files or Information · Defense Evasion
T1414 Clipboard Data · Credential Access + Collection
T1421 System Network Connections Discovery · T1422 Network Config · T1424 Process Discovery · T1426 System Info · T1430 Location Tracking
T1409 Stored Application Data · T1429 Audio Capture · T1430 Location Tracking
File system: /data/user/0/am.a.myth/shared_prefs/*.xml
Zenbox hash: 0ccbc8037779bbd9be68dff169f14050
checks-gpsobfuscatedreflectiontelephony
Still not sure? Scan yourself.

Download the APK from the homepage, upload to virustotal.com, and match the hashes above.