What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
- Current default decompiler backend and any alternatives: confirm against project README
- Shipped pattern file contents change over time: confirm current coverage
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
APKLeaks is a small Python command line tool that takes an Android package, decompiles it, and greps the result for strings that should never have shipped in a distributed binary. It drives an external Java decompiler to turn DEX bytecode back into readable sources, then walks every produced file along with the manifest and resource entries.
The regular expression set is the substance of the tool. The bundled pattern file covers cloud provider access keys, third party service tokens, Firebase and object storage URLs, internal hostnames, and generic high entropy strings that look like credentials. You can supply your own pattern file, which is how most teams use it after the first run, adding the naming conventions their own backend services use. Output can be written as JSON for whatever pipeline you already run.
Where it fits
This is a triage step, not an assessment. Run it as the first thing you do when an APK lands on your desk, before you open a decompiler yourself, so you know whether there is low hanging fruit. It also works as a pipeline job against every signed release artifact, failing the build when a new key appears. A JDK has to be present for the decompiler backend, and someone has to own the pattern file, otherwise it drifts and stops matching your organization's secret formats.
Strengths
- Turns a multi step workflow, decompile then search, into one command with JSON output.
- The pattern file is plain data, so tuning detection for your own token formats takes minutes rather than a code change.
- Fast enough to run on every build without becoming the slowest stage in the pipeline.
- Small dependency footprint and no service to stand up, which makes it easy to approve for use on client artifacts.
Limitations
- Regular expression matching over decompiled code produces noise. Test fixtures, sample keys in vendor SDKs and public identifiers all match, and nobody triages that for you.
- It cannot see secrets that are assembled at runtime, decrypted from a native library, or fetched from a server after first launch, which is exactly where a careful developer puts them.
- Results depend entirely on the decompiler succeeding. Heavily obfuscated or packed applications degrade the output and the scan quietly finds less.
Who it suits
Mobile penetration testers who want a fast first pass, and Android teams who want a cheap gate that catches the obvious credential commit before an APK reaches a store listing. It is not a mobile application security testing platform, and a team expecting managed triage, dynamic analysis or compliance reporting should look at a full framework instead.
Used APKLeaks? Recommend it under your own name and title.
Recommend this tool