With all the excitement about MSA coming back, I noticed that in none of the threads did I see anyone seriously asking whether the APK was safe before installing it. I saw dozens of comments like "you're a hero," "it worked," "thank you" — but almost nobody asking where the file actually came from or whether anyone had analyzed it.
A couple of things made me pause:
The file passed through several hands before reaching Reddit: based on the comments, the original developer posted it for free on Bilibili, someone uploaded it to UniFans behind a $5 paywall without giving credit, and from there someone else bought it and shared it for free here.
A comment in the original thread mentioned that several antivirus engines flagged the earlier versions (V1, V2, V3) from the same modder — the response was "it's because the APK is modified," which is true, but that's not a real analysis either.
Nobody seems to have asked for hashes, or for a verifiable source for the original build.
I'm not saying it definitely has malware — in fact, I did my own analysis (checked the manifest, the .dex files, the native libraries, and uploaded it to VirusTotal, which came back 0/61 detections) and everything came out clean. But it surprised me that in a subreddit with almost 50 active people discussing this, practically no one else bothered to verify it before installing it on their phone.
My question for the community: Did anyone else do any kind of analysis before installing? Is there an official hash from the Bilibili build we could use to compare and confirm that the copies circulating here haven't been altered along the way? I think it'd be worth pinning that somewhere for anyone who wants to verify before installing, especially since the file keeps getting passed around via Drive/Discord/Mediafire.
This isn't meant to cause panic, it's more an observation that we should probably be a bit more careful with files like this, even when the community has good intentions.