The Skeleton Keys: A Large Scale Analysis of Credential Leakage in Mini-apps

Yizhe Shi

Network and Distributed System Security (NDSS) Symposium 2025 · Day 1 · Mobile Security

Overview

This talk, presented by Yizhe Shi from Fudan University, delves into the pervasive and critical issue of credential leakage within the rapidly expanding super-app and mini-app ecosystem. The presentation introduces K-Magnet, a novel semantic analysis framework designed to systematically identify and analyze these vulnerabilities at scale. The core problem addressed is that while super-apps offer mini-apps access to sensitive resources and services via credential-based access control, a significant lack of security awareness among mini-app developers leads to improper sharing of these critical credentials with client-side code.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction: Mini-apps, super-apps, and credential leakage problem
  2. 2:00 Why existing credential leakage detection methods are insufficient
  3. 3:00 K-magnet: Proposing a semantic analysis approach for detection
  4. 3:50 Methodology: Learning server-side and client-side semantics
  5. 6:00 K-magnet's evaluation performance and high F-score results
  6. 7:00 Statistics: Discovering over 8,000 credential leakage issues
  7. 8:20 Real-world security hazards: Account hijacking, payment deception

The Skeleton Keys: A Large Scale Analysis of Credential Leakage in Mini-apps

Speakers: Yizhe Shi

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=n8N1hAQSb2s

Overview

This talk, presented by Yizhe Shi from Fudan University, delves into the pervasive and critical issue of credential leakage within the rapidly expanding super-app and mini-app ecosystem. The presentation introduces K-Magnet, a novel semantic analysis framework designed to systematically identify and analyze these vulnerabilities at scale. The core problem addressed is that while super-apps offer mini-apps access to sensitive resources and services via credential-based access control, a significant lack of security awareness among mini-app developers leads to improper sharing of these critical credentials with client-side code.

The significance of this research cannot be overstated. With billions of users relying on popular super-app platforms like WeChat and Alipay, leaked credentials expose individuals to severe risks, including account hijacking, payment deception, and phishing attacks. Traditional credential leakage detection methods, which often rely on hardcoded patterns or fixed formats, are largely ineffective against the dynamically retrieved and often unstructured credentials prevalent in the mini-app environment. K-Magnet fills this critical gap by understanding and comparing the semantic behavior of credentials on both the server and client sides, offering a robust solution to a widespread and previously underestimated security challenge.

Background

▶ Watch: Introduction: Mini-apps, super-apps, and credential leakage problem (0:00)

The modern mobile landscape has witnessed a significant shift towards the super-app paradigm, where a single, overarching application (the super-app) hosts a multitude of smaller, independent applications known as mini-apps. This architecture streamlines development, user experience, and data management, offering mini-app developers a rich array of sensitive resources and services provided by the super-app platform. These services range from payment processing and AI capabilities to cloud storage, all of which are crucial for the functionality of most mini-apps.

To safeguard these sensitive services, super-apps implement a credential-based access control mechanism. Before a mini-app server can access a super-app service, it must first retrieve a specific credential from the super-app platform. This credential is then included in requests sent to the super-app service, which verifies it before approving the request. This system is fundamentally sound in principle, but its security hinges on the proper handling of these credentials by mini-app developers.

The primary vulnerability arises from a widespread lack of security awareness among mini-app developers regarding the importance and secure management of these credentials. Many developers, either due to convenience or misunderstanding, improperly share these critical credentials with their mini-app clients. Once a credential resides on the client side, it becomes highly susceptible to interception and exploitation by attackers. This allows malicious actors to directly access sensitive super-app services, leading to a host of severe security consequences such as privacy breaches and account hijacking.

Existing techniques for detecting credential leakage primarily focus on hardcoded and well-structured credentials. For instance, methods designed to detect leaked AWS keys often look for fixed prefixes like "AKIA." While effective for such specific cases, these methods suffer from high rates of false positives and false negatives when applied to the mini-app ecosystem. The credentials used in super-app environments are predominantly dynamically retrieved from the server side and do not adhere to a unified or fixed format. This inherent variability makes traditional pattern-matching and signature-based detection approaches largely ineffective. The challenge, therefore, is to develop a detection mechanism that can identify leakage of these dynamic, often amorphous credentials, bridging the gap between how they are intended to be used on the server and how they are misused on the client.

Key Findings

▶ Watch: K-magnet: Proposing a semantic analysis approach for detection (3:00)

The research presented in "The Skeleton Keys" uncovered a startling prevalence of credential leakage within the super-app and mini-app ecosystem, illustrating a significant security oversight. Through an extensive analysis targeting 21 popular super-app platforms, the researchers manually examined developer documentation and identified a taxonomy of 64 types of critical credentials. These were systematically grouped into three main categories: root credentials, access credentials, and cryptographic credentials, each with distinct implications for security if compromised.

The large-scale analysis conducted using K-Magnet revealed an alarming number of vulnerabilities, with over 8,000 credential leakage issues detected across the sampled mini-apps. This figure underscores that credential leakage is not an isolated incident but a widespread and systemic problem affecting the entire mini-app ecosystem. The leakage was found to be prevalent across various major platforms, including prominent ones like WeChat and Alipay. Among the identified credential types, access credentials were the most frequently leaked. This is largely attributed to mini-app developers often sending these credentials to the client side to facilitate access to different super-app services, directly contributing to the leakage problem.

Beyond the sheer volume of leaks, the study also yielded several insightful observations about the nature and patterns of these vulnerabilities:

  • Cross-Platform Similarities: Many mini-apps, even those deployed across different super-app platforms, exhibited similar leakage patterns. This was particularly evident among mini-apps developed by the same organizations or components, suggesting a shared development culture or codebase contributing to the vulnerabilities.
  • Template-Based Vulnerabilities: A notable portion of vulnerable mini-apps were found to be developed using common mini-app templates. These templates, designed to accelerate development, inadvertently propagate security misconfigurations or insecure coding practices, leading to widespread leakage across applications built upon them.
  • Functionality-Specific Risks: Certain functional scenarios within mini-apps were identified as having a higher propensity for credential leakage. For instance, mini-apps involved in login scenarios and those that generate or handle QR codes were found to be particularly vulnerable, likely due to their direct interaction with user authentication or sensitive data exchange.

To quantify the potential impact of these leakages, the researchers conducted a manual analysis of developer documentation to understand what sensitive services could be accessed by attackers leveraging leaked credentials. They identified 15 distinct types of services that, when compromised, could lead to severe security hazards. These hazards include, but are not limited to, account hijacking, payment deception, and sophisticated phishing attacks. The prevalence and severity of these findings highlight the urgent need for improved security practices and robust detection mechanisms within the mini-app development landscape.

Technical Deep Dive

▶ Watch: Methodology: Learning server-side and client-side semantics (3:50)

The core innovation of this research lies in K-Magnet, a sophisticated semantic analysis framework designed to detect credential leakage in mini-apps. Recognizing the limitations of existing techniques that fail against the dynamic and unstructured nature of mini-app credentials, K-Magnet proposes a novel approach centered on comparing the semantics of credential usage. The fundamental idea is that while credentials might be improperly shared from the mini-app server to the client, their underlying behavior when interacting with super-app services will remain similar on both sides. By modeling and comparing these semantic behaviors, K-Magnet can identify instances where server-side credential semantics inappropriately manifest on the client side, signaling a potential leakage.

K-Magnet operates through a three-phase semantic analysis process:

Phase 1: Learning Server-Side Semantics

The initial challenge in understanding server-side credential semantics is that most relevant operations run in the background, making them difficult to directly observe or analyze. K-Magnet overcomes this by leveraging developer documentation. Super-app platforms typically provide extensive documentation detailing credential interfaces, their parameters, and their intended usage.

  • Document Analysis: K-Magnet performs an automated analysis of this documentation to track elements related to credentials, such as API calls, authentication mechanisms, and expected data flows.
  • Credential Semantic Graph (CSG): The extracted information is then used to construct a Credential Semantic Graph (CSG). A CSG is a graph structure where nodes represent credential elements (e.g., API keys, tokens, specific parameters) and edges represent the relationships and interactions between these elements within the API-level interfaces. This graph effectively models how credentials should be handled and used on the secure server side, representing the "ideal" or intended semantic behavior.

Phase 2: Learning Client-Side Semantics

To determine if credentials are being improperly exposed, K-Magnet needs to understand how they are handled on the mini-app client side. This phase involves a detailed analysis of the mini-app's client-side code and its execution behavior.

  • Fine-Grained Data Flow Analysis: K-Magnet conducts a fine-grained data flow analysis on the mini-app's executable code. This analysis tracks the propagation and transformation of data within the mini-app, particularly focusing on network data and other behaviors crucial for credential handling.
  • API Modeling: The framework models the specific APIs provided by different super-app platforms that mini-apps can invoke. This allows K-Magnet to understand the context and purpose of various client-side operations.
  • Interprocedural Control-Flow Graph (ICFG): For each mini-app, an Interprocedural Control-Flow Graph (ICFG) is constructed. This graph captures the flow of control and data across different functions and procedures within the mini-app.
  • Client-Side Behavior Graph (CBG): Similar to the CSG, a Client-Side Behavior Graph (CBG) is generated. The CBG encompasses two types of nodes: framework interfaces (APIs provided by the super-app platform) and customized client-side interfaces (functions and methods implemented by the mini-app developer). Edges in the CBG represent data dependencies between these nodes, illustrating how data (including potential credential information) flows and is processed on the client side. This graph represents the actual semantic behavior observed on the client.

Phase 3: Semantic Comparison

With both the ideal server-side semantics (CSG) and the actual client-side semantics (CBG) modeled as graphs, the final phase involves comparing them to detect leakage.

  • Semantic Isomorphism: The objective is to determine whether the semantics represented by the CSG "exist" as a subgraph within the CBG. This is conceptualized as a semantic isomorphism problem. However, a direct graph isomorphism comparison is challenging because the graphs are constructed from different perspectives (API-level documentation vs. code-level data flow) and thus may not have direct node-to-node correspondence.
  • Semantic-Based Isomorphism Algorithm: To address this gap, K-Magnet employs a specialized semantic-based isomorphism algorithm. While the specific details are elaborated in the research paper, this algorithm is designed to intelligently probe for semantic similarities and structural correspondences between the CSG and CBG, even when direct mapping is not straightforward. If a significant semantic overlap or correspondence is found where server-side credential handling patterns are mirrored on the client side, K-Magnet flags it as a potential credential leakage.

The evaluation of K-Magnet's performance, although lacking ground truth, involved sampling 500 mini-apps identified as both vulnerable and non-vulnerable. The results indicated strong performance across all super-app platforms, with an average F-score exceeding 90%. This demonstrates K-Magnet's effectiveness in accurately identifying credential leakage issues, significantly outperforming prior methods by tackling the unique challenges posed by the dynamic and unstructured nature of mini-app credentials.

Demo / Proof of Concept

▶ Watch: Statistics: Discovering over 8,000 credential leakage issues (7:00)

While the talk did not feature a live, interactive demo in the traditional sense, the speaker effectively illustrated the tangible security hazards caused by credential leakage through a detailed account hijacking scenario enabled by a compromised cryptographic credential. This served as a compelling proof of concept for the real-world impact of the vulnerabilities K-Magnet detects.

The scenario unfolds as follows:

  1. Convenient Login Feature: Many super-apps offer a convenient login feature for mini-apps, allowing users to log in seamlessly without re-entering credentials.
  2. Encrypted Phone Data: Technically, when a mini-app user attempts to log in, the mini-app client first retrieves encrypted phone data from the super-app platform. This encrypted data is then sent to the mini-app server.
  3. Server-Side Decryption: The mini-app server is responsible for receiving this encrypted phone data, decrypting it, verifying the phone number, and subsequently returning an authentication token bound to that verified phone number, thereby logging the user into their account.
  4. The Attack: The vulnerability arises when the cryptographic credential (e.g., an encryption key or token required for decryption) is leaked to the mini-app client. An attacker, having obtained this credential from the client, can then intercept the communication. Instead of sending the legitimate encrypted phone data, the attacker can temper the inquired phone data with any other phone number of their choosing.
  5. Hijacking: The attacker then sends this manipulated, but still cryptographically valid, data to the mini-app server. Because the server possesses the legitimate cryptographic credential and expects to decrypt valid data, it proceeds to decrypt the tempered phone number. It then returns an authentication token that is bound to the attacker's chosen (hijacked) phone number.
  6. Consequence: With this token, the attacker can effectively hijack any other user's account simply by knowing their phone number. This grants them unauthorized access to sensitive user information, such as status updates, educational details, and potentially other private data associated with the compromised account.

The speaker also clarified that to evaluate these "secret impacts," they developed their own mini-apps to test whether they could successfully access or manipulate their own information, thus confirming the feasibility and severity of such attacks when credentials are leaked. This practical demonstration underscores the critical need for robust credential management and leakage detection.

Defensive Implications

▶ Watch: Real-world security hazards: Account hijacking, payment deception (8:20)

The findings from "The Skeleton Keys" provide clear and actionable insights for both mini-app developers and super-app platform providers to enhance security and mitigate the pervasive threat of credential leakage.

For mini-app developers, the primary and most crucial defensive implication is to fundamentally change their approach to credential handling:

  • Strict Server-Side Usage: Credentials, especially those providing access to sensitive super-app services, must only be used and processed on the mini-app server-side. They should never be transmitted to, stored on, or processed by the mini-app client. The talk explicitly highlights this as a key mitigation: "the mini-app developers should only use the credentials in the mini-app server side and they don't need to send the credential to the client side which can be obtained by the attackers."
  • Security Awareness Training: Developers need improved education and training on the principles of secure credential management, understanding the severe risks associated with client-side exposure.
  • Secure Development Practices: Adopting secure coding guidelines, utilizing secure APIs provided by super-app platforms, and avoiding insecure mini-app templates can help prevent these vulnerabilities from being introduced.
  • Regular Security Audits: Mini-app developers should conduct regular security audits and penetration testing of their applications, focusing specifically on data flow and credential handling, to proactively identify and rectify leakage issues.

For super-app platforms, their role is equally critical in fostering a more secure ecosystem:

  • Enhanced Developer Education: Platforms should provide clearer, more prominent, and more actionable security guidelines within their developer documentation, specifically addressing the risks of credential leakage and best practices for server-side handling.
  • Secure API Design: Designing APIs that inherently minimize the need for client-side credential exposure, perhaps through token-based authentication mechanisms that are short-lived or bound to specific client sessions, can reduce risk.
  • Static/Dynamic Analysis Tools: Super-app platforms could integrate K-Magnet-like static and dynamic analysis tools into their mini-app submission and review processes. This would allow them to automatically scan mini-apps for credential leakage before they are deployed to users, acting as a critical gatekeeper.
  • Runtime Protections: Implementing runtime environment protections that detect and prevent unauthorized access to sensitive super-app services from mini-app clients based on behavioral anomalies could provide an additional layer of defense.
  • Credential Lifecycle Management: Providing robust tools and services for mini-app developers to securely manage the entire lifecycle of their credentials, from issuance to rotation and revocation, can further reduce the attack surface.

Ultimately, a multi-faceted approach involving better developer education, stricter platform controls, and the adoption of advanced detection tools like K-Magnet is essential to safeguard the integrity and security of the rapidly expanding super-app and mini-app ecosystem.

Key Takeaways

  • Pervasive Leakage: Credential leakage is a widespread and significant security problem within the super-app and mini-app ecosystem, affecting thousands of applications and multiple major platforms.
  • Inadequate Existing Methods: Traditional credential detection techniques are ineffective against the dynamic, server-side retrieved, and often unstructured credentials used in mini-apps.
  • K-Magnet's Novel Approach: K-Magnet introduces a pioneering semantic analysis framework that detects leakage by comparing the intended server-side credential semantics with the actual client-side behavior.
  • Severe Security Risks: Leaked credentials lead to critical security hazards, including account hijacking, payment deception, and phishing attacks, impacting user privacy and financial security.
  • Server-Side Imperative: Mini-app developers must restrict the use of sensitive credentials exclusively to the mini-app server-side and never expose them to the client.
  • Platform Responsibility: Super-app platforms have a crucial role in providing better security guidance, enforcing stricter policies, and potentially integrating advanced detection tools to protect users.

About the Speaker(s)

Yizhe Shi is a researcher from Fudan University. His work focuses on systematically studying the credential system in the super-app and mini-app ecosystem, developing novel approaches for detecting credential leakage, and conducting large-scale analyses of associated security risks.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Solid academic security research with real numbers, a novel detection framework, and a large-scale measurement study that actually quantifies a problem most practitioners haven't formally mapped yet. The super-app/mini-app credential landscape is genuinely underexplored in Western security research, and 8,000+ leakage instances across 21 platforms with a working tool and 90%+ F-score is a credible contribution — not just a theoretical exercise.

Heather Calloway (CISO) — WEAK

Technically credible research that documents a real, scalable credential mismanagement problem across a high-exposure ecosystem. But it stops at the research boundary — the institutional accountability question, the platform governance failure, and the operator decision path are all left on the table.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025