Huge News!Announcing our $40M Series B led by Abstract Ventures.Learn More
Socket
Sign inDemoInstall
Socket

jail-monkey

Package Overview
Dependencies
Maintainers
5
Versions
26
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

jail-monkey

A React Native module for identifying jail-broken, rooted, or mock locations on iOS and Android

  • 2.8.0
  • latest
  • Source
  • npm
  • Socket score

Version published
Maintainers
5
Created
Source

WARNING: I don't have the devices to test anymore, so testing is done by those submitting PRs bona fide.

Jail Monkey

Version Downloads

Can you ever really trust a phone?

Why?

Are users claiming they are crossing the globe in seconds and collecting all the Pokeballs? Some apps need to protect themselves in order to protect data integrity. JailMonkey allows you to:

  • Identify if a phone has been jail-broken or rooted for iOS/Android.
  • Detect mocked locations for phones set in "developer mode".
  • (ANDROID ONLY) Detect if the application is running on external storage such as an SD card.

Use

import JailMonkey from 'jail-monkey'

if (JailMonkey.isJailBroken()) {
  // Alternative behaviour for jail-broken/rooted devices.
}

Circle of Trust

API

MethodReturnsDescription
isJailBrokenbooleanis this device jail-broken/rooted.
canMockLocationbooleanCan this device fake its GPS location.
trustFallbooleanChecks if the device violates either isJailBroken or canMockLocation.
isDebuggedModePromise<boolean>Is the application is running in debug mode. Note that this method returns a Promise.

iOS Only APIs

MethodReturnsDescription
jailBrokenMessagestringReturns the reason for jailbroken detection. Will return an empty string on Android.

Android Only APIs

MethodReturnsDescription
hookDetectedbooleanDetects if there is any suspicious installed applications.
isOnExternalStoragebooleanIs the application running on external storage (ie. SD Card)
AdbEnabledbooleanIs Android Debug Bridge enabled.
isDevelopmentSettingsModePromise<boolean>Whether user has enabled development settings on their device. Note that this method returns a Promise.
androidRootedDetectionMethodsRootedDetectionMethodsReturns an object with the results of all the Android rooted detection methods for more granular detection, this can be helpful if some devices are giving false positives.
type RootedDetectionMethods = {
  rootBeer: {
    detectRootManagementApps: boolean;
    detectPotentiallyDangerousApps: boolean;
    checkForSuBinary: boolean;
    checkForDangerousProps: boolean;
    checkForRWPaths: boolean;
    detectTestKeys: boolean;
    checkSuExists: boolean;
    checkForRootNative: boolean;
    checkForMagiskBinary: boolean;
  },
  jailMonkey: boolean;
}

On iOS all of the Android only methods will return false or Promise<false> where appropriate.

:exclamation: Since emulators are usually rooted, you might want to bypass these checks during development. Unless you're keen on constant false alarms :alarm_clock:

Install

npm i jail-monkey --save
react-native link # Not required as of React Native 0.60.0

for iOS:

cd ios && pod install

If you use rnpm, you may have trouble as rnpm does not link Android properly after 0.29.0!

Note: On Android you should include location.isFromMockProvider() from your location provider to compliment JailMonkey.canMockLocation(). Most react-native location libraries already have this check built in

Additional Info

This has been made public to help keep it up to date. As detection measures get better or out-dated, please send updates to this project so it can be the best method of detection.

Special thanks to this fantastic blog article: http://blog.geomoby.com/2015/01/25/how-to-avoid-getting-your-location-based-app-spoofed/

Keywords

FAQs

Package last updated on 09 Dec 2022

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc