# Specter: a unified Play Integrity and root-hiding stack for Android

> Specter is a Magisk-style Android module that coordinates Play Integrity spoofing, keybox management and root hiding behind one WebUI. It is GPL-3.0, requires root, and its own README warns that nothing about hiding is guaranteed.

**dpejoh/specter** — Unified Play Integrity and root hiding stack for Android

- Repository: https://github.com/dpejoh/specter
- Website: https://specter.dpejoh.com
- Stars: 709 · Forks: 51
- Language: TypeScript
- License: GPL-3.0
- Published: 2026-09-18 · Updated: 2026-09-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/dpejoh-specter

## What Specter coordinates on a rooted phone

Passing Google's Play Integrity checks on a rooted Android phone normally means installing and hand-tuning several separate modules: a keybox provider, a Play Integrity fingerprint spoofer, a root hider, and the configuration that keeps them from fighting each other. Specter, written in TypeScript and packaged as a Magisk, KernelSU or APatch module, puts that coordination behind one WebUI. It is the rewrite of what the author previously shipped as Yurikey. The target user runs a rooted device and wants integrity checks to pass for apps that refuse to run on modified systems, without assembling the stack by hand. The README is candid about the context: a legal notice states the tool is for educational use, and a warning spells out that root always carries risk, warranties may be voided and account bans are possible.

## How the first-boot pipeline and conflict resolution work

Specter does not replace the underlying modules; it orchestrates them. It sits on top of Tricky Store, TEESimulator or a variant, and a Play Integrity Fix build, driving their configuration. On first boot the README describes a pipeline that runs once: back up the originals, set app targeting, apply the security patch, and install the keybox. From there the WebUI exposes the moving parts: a multi-source keybox catalog with backup and restore and a Google revocation check, automatic targeting of new apps via inotify and polling, per-app targeting states, live security-patch fetching with an offline fallback, and ROM fingerprint cleaning. The piece that matters most in practice is conflict resolution across eight modules, where aggressive detectors are disabled, passive ones are allowed to coexist, and feature ownership is assigned, so the stack does not undo its own work.

## Installing the module and its dependencies

Installation follows the README's quick start and depends on already having root through Magisk, KernelSU or APatch. The order is: install Tricky Store, TEESimulator or TEESimulator-RS (Specter auto-installs TEESimulator-RS if none is found); install Play Integrity Inject or Play Integrity Fork; install Specter through your root manager; reboot, which triggers the first-boot pipeline; then open the WebUI. The README gives no shell command sequence for installation beyond flashing the module packages through the root manager, which is why the steps read as a checklist rather than a script. Once rebooted, the WebUI is where you confirm the keybox status, pick or blacklist a Pixel Canary target, and check the action, boot and live logs that v1.5.0 moved into a dedicated viewer.

## Building the module from TypeScript source

If you want to build Specter yourself rather than flash a release, the README gives a standard Node workflow:
```bash
git clone https://github.com/dpejoh/specter
cd specter
npm install
npm run build
```
That produces a Specter-v{version}.zip you can flash. The project takes its own testing seriously for a module of this kind. The README documents a shell test suite and a TypeScript suite you can run directly:
```bash
bash tests/run.sh
npm test
npx tsc --noEmit
```
CI runs TypeScript in strict mode, ShellCheck, both test suites, and structure checks that reject hardcoded module paths and su -c calls in feature scripts. That last rule is a deliberate safety constraint on how feature code is allowed to invoke privilege.

## The moving-target problem and ban risk

The honest limitation is structural, not a bug. Play Integrity is a moving target: Google revokes leaked keyboxes and changes its checks, so any spoofing stack degrades over time and needs new keyboxes and fingerprints to keep working. Specter's own keybox catalog includes a Google revocation check precisely because revocation happens. The README does not promise success; its warning says nothing is one hundred percent guaranteed, that apps may break and that account bans are possible. That is the real risk model. If you depend on a banking or streaming app that actively hunts for modified devices, using this stack can get that account flagged, and no amount of configuration removes that possibility. This is a tool for people who accept that trade, not a way to make a rooted phone indistinguishable from a stock one for good.

## Specter versus wiring Tricky Store and PIF by hand

The direct alternative is running the same underlying modules yourself: install Tricky Store, add a Play Integrity Fix build, source a keybox, and edit each module's configuration until integrity passes. That path gives you full visibility into every setting and no extra abstraction layer, which some users prefer. What you give up is the coordination Specter adds: the conflict resolution across eight modules, the first-boot pipeline, the automatic app targeting, and a WebUI that surfaces keybox status and logs in one place. Doing it by hand also means you own the job of keeping the pieces from interfering, which is exactly the failure mode Specter's feature-ownership logic is built to prevent. The choice is between manual control and managed coordination of the same components.

## GPL-3.0 and how fast it moves

Specter is licensed under GNU GPL v3.0, so you can study, modify and redistribute it under the same terms, which is a clearer footing than the no-license and NOASSERTION cases common in this space. The last push was on 2026-09-17, and the release history is frequent: v1.5.0 on 2026-09-12 followed several point releases in early September, each fixing specific issues such as a targeting deadlock that pinned a CPU core. That cadence matters here more than for most software, because a root-hiding stack that stops being updated stops working as Google's checks change. The translation workflow is automated through Crowdin, with weekly pull requests importing finished strings, so localization keeps pace without manual merges.

## Conclusion

Adopt Specter if you run a rooted Android phone through Magisk, KernelSU or APatch and want one WebUI to coordinate Tricky Store, Play Integrity Fix and keybox management instead of wiring them by hand. Do not use it on a device tied to an account you cannot risk, since the README itself warns that bans are possible and nothing is guaranteed. Before installing, confirm your root manager and the required dependency modules are in place, because Specter orchestrates that stack rather than replacing it, and a missing keybox provider leaves the first-boot pipeline with nothing to configure.

## FAQ

### What is Specter for Android?

Specter is a Magisk, KernelSU or APatch module, written in TypeScript, that coordinates Play Integrity spoofing, keybox management and root hiding behind one WebUI. It is a rewrite of the author's earlier Yurikey.

### What does Specter require to run?

Root access through Magisk, KernelSU or APatch, plus a keybox provider such as Tricky Store or TEESimulator and a Play Integrity Fix build. Specter auto-installs TEESimulator-RS if none is detected.

### Can Specter guarantee Play Integrity always passes?

No. Its own README states nothing is guaranteed, apps may break and account bans are possible. Google revokes leaked keyboxes and changes checks, so the stack needs ongoing updates to keep working.

### What license is Specter under?

Specter is released under GNU GPL v3.0, which lets you study, modify and redistribute it under the same terms.

## Sources

- [dpejoh/specter on GitHub](https://github.com/dpejoh/specter)
- [License: GPL-3.0](https://github.com/dpejoh/specter/blob/main/LICENSE)
- [Project website](https://specter.dpejoh.com)
- [README](https://github.com/dpejoh/specter/blob/main/README.md)
- [Releases](https://github.com/dpejoh/specter/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/dpejoh-specter
