3 ms·
Similar to what netsharc describes Found the call that added the header for the API key to each request (even with Proguard's obfuscation string literals are p
by selpop 7y ago
Similar to what netsharc describes
Found the call that added the header for the API key to each request (even with Proguard's obfuscation string literals are preserved, so searching for "x-api-key" worked)
From there I followed the call chain to their transformer, then looked at the input for the transformer and it was loading a subset of bytes read from the same resource as the launcher icon (and sure enough, opening it in a hex editor there was some weird "garbage" that I'm honestly surprised Android doesn't choke on)