finds.dev← search

// the find

CreditTone/hooker

★ 5,304 · JavaScript · updated Sep 2026

🔥🔥 hooker is a Frida-based reverse engineering toolkit for Android. It offers a user-friendly CLI, universal scripts, auto hook generation, memory roaming to detect activities/services, one-click SOCKS5 proxy setup, Frida JustTrustMe, and BoringSSL unpinning for all apps.

hooker is a Frida-based CLI toolkit for Android reverse engineering that wraps common tasks - SSL unpinning, script generation, memory/activity roaming, SOCKS5 proxying, and an injectable HTTP server - into a single interactive shell. It's aimed at people doing app traffic analysis, protocol reverse engineering, or crawler/API extraction work on rooted Android devices, not general mobile security researchers looking for a polished framework.

The auto-generated hook scripts (gs command) produce real usable Frida JS with stack traces and call-through wrappers, saving the tedious boilerplate of writing overload-matching hooks by hand. The embedded webserver with annotation-based routing (@HookerController, @HookerRequestMapping) is a genuinely clever idea - turning an app's internal Java methods into HTTP endpoints without manual JNI/reflection gymnastics is a real time-saver for API extraction work. Bundling frida-server binaries, r0capture, iptables-based transparent SOCKS5 proxying, and JustTrustMe/BoringSSL unpinning into one CLI removes a lot of separate tool juggling that reverse engineers normally do by hand.

Almost all documentation is Chinese-only (README_EN exists but the bulk of detail, examples, and community activity clearly centers on Chinese app targets like Taobao, Douyin, Meituan), which will slow down adoption for non-Chinese speakers despite the translated README. The tool bundles compiled binaries (frida-server, busybox, frpc, redsocks) directly in the repo rather than fetching them, meaning version updates require a full git pull and there's no clear checksum/signing story for a tool that runs with root on your device. It's built for a fairly narrow workflow (rooted device + USB + specific frida version pinned at 16.7.19) with no mention of test coverage, and the 'auto-update via git pull average 10x/week' cadence suggests instability and breaking changes are common rather than exceptional. Legal risk is real and explicitly disclaimed - this is a tool for bypassing app protections, and adopting it means owning that risk yourself since the project won't.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →