Follow us on Telegram for the latest updates: https://t.me/mothershipsg
Malaysia's Covid-19 contact tracing app, MySejahtera, was recently compromised to send out Rick Roll memes and fake Covid-19 positive messages to users in Malaysia, Malaysiakini reported.
The loophole in the application's script was highlighted on Oct. 18 by a full-stack developer working in Singapore, Phakorn Kiong.
Amid worries of potential leak of users' personal information, MySejahtera took to Twitter on Oct. 20 to assure users that "no user data was assessed".
Health Ministry said the app's security has been beefed up
MySejahtera is a mobile application developed by the Malaysian government to facilitate contact tracing for Covid-19 cases and verify users' vaccination statuses, similar to Singapore's TraceTogether.
In a statement, Malaysia's Ministry of Health (KKM) confirmed that it received complaints about spam emails and OTP (One-Time Password) messages that required users to verify their registered personal phone numbers.
KKM explained that the problem was due to people misusing the API (Application Programming Interface) to send out those messages via the app, and elaborated that the app's database was not compromised.
"In response to the irresponsible actions, the MySejahtera team has strengthened the MySejahtera app and website to prevent similar incidents from occurring again," KKM added.
"Anyone" could access the system
Speaking to Malaysiakini, Kiong said the app initially failed to secure the API with proper authentication methods, which allowed "anyone" to access and potentially abuse the system.
Kiong reportedly proved his statement by accessing the MySejahtera system to send an email to the news site.
He added that "bad faith actors" could pose as an official source and send emails with bad intentions to the app's users.
Spam emails featuring "Rickroll"
Meanwhile, Twitter users have shared their experiences in receiving spam emails and messages that appeared to be from MySejahtera.
A netizen posted a screenshot of an OTP on her phone, with numerous people stating similar occurrences.
Donβt tell me, people are hacking #MySejahtera app too π΅βπ« @KKMPutrajaya @kkmm_gov @Khairykj @AnnuarMusa pic.twitter.com/m6PvfY5fcN
— Kavita Maheendran (@kavitamaheendra) October 18, 2021
A journalist received a spam email that wrote, "You've tested positive for covid nahhh, joking. Plenty of exploits to show."
Just heard about how @my_sejahtera's database is compromised, & right on time I got a troll email from its helpdesk. pic.twitter.com/hvOjttwAI5
— Zurairi A.R. (@zurairi) October 20, 2021
"Rickroll" memes were also seen in some spam emails that appeared to be sent via MySejahtera.
Just realised we have been getting these emails since Sunday, complete with Rickrolls π pic.twitter.com/0dQSOL5zws
— Zurairi A.R. (@zurairi) October 20, 2021
Instructions on how to game the system was even posted on Malaysian online forum lowyat.net, where many proceeded to call out the team behind the "RM70 million" (S$22.6 million) app.
At the time of writing, it is unclear whether the problem has successfully been resolved.
Follow and listen to our podcast here
Top image via MySejahtera/Facebook & @zurairi/Twitter
If you like what you read, follow us on Facebook, Instagram, Twitter and Telegram to get the latest updates.