Convenience at a Cost: the Security Risks of Template-Based Development in the App-in-App Ecosystem
Yizhe Shi, Zhemin Yang, Yifan Yang, Yunteng Yang, Min Yang
Abstract
Recently, many popular mobile applications, such as WeChat and Alipay, have evolved into super-apps, with numerous merchants tending to develop their own mini-apps to enhance user experience. To overcome the limited development capabilities of individual merchants, super-apps allow thirdparty service providers to create mini-apps for them using templates, which enable the rapid development of mini-apps for various merchants. However, this template-based development mechanism also introduces significant security concerns, as many mini-apps created using templates exhibit malicious behaviors. In this work, we present the first systematic study focused on assessing the malicious behaviors associated with mini-app templates. We design and implement a novel tool, mateminer, which adopts a three-stage clustering analysis and differential analysis to extract mini-app templates from a large dataset of mini-apps. Furthermore, we propose a pattern-based method to detect malicious behaviors. Finally, we apply MateMiner to 2,282,096 mini-apps and identify malicious behaviors in 79,758 mini-apps and 4,642 mini-app templates. Our results reveal that the templates have been abused to facilitate the development of malicious mini-apps, with most malicious behaviors targeting user privacy. This study highlights the security risks associated with templatebased development and provides a foundation for detecting and mitigating such threats. Furthermore, we have reported all our findings to the super-app platform.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 82fd6fb5-be7b-41e6-91cf-be1b8e69f31bRelated papers
- Cross Miniapp Request Forgery: Root Causes, Attacks, and Vulnerability DetectionYuqing Yang, Yue Zhang, Zhiqiang LinCCS 2022 · 29 citations
- Real or Rogue? Detecting Malicious Miniapps with Deceptive Reporting InterfaceYuqing Yang, Zhiqiang LinWWW 2026
- Understanding Miniapp Malware: Identification, Dissection, and CharacterizationYuqing Yang, Yue Zhang, Zhiqiang LinNDSS 2025
- One Size Does Not Fit All: Uncovering and Exploiting Cross Platform Discrepant APIs in WeChatChao Wang, Yue Zhang, Zhiqiang LinUSENIX Security 2023
- Taintmini: Detecting Flow of Sensitive Data in Mini-Programs with Static Taint AnalysisChao Wang, Ronny Ko, Yue Zhang, Yuqing Yang et al.ICSE 2023 · 36 citations
