Library / SDK
frknkrc44/HMA-OSS avatar
frknkrc44/HMA-OSS

HMA-OSS: a Zygisk module that hides your app list from other apps

A Zygisk module to hide your app list, settings, package installers and more. It is a fork of Hide My Applist project, but LSPosed dependency is replaced with Zygisk.

3,398 stars223 forksKotlinAGPL-3.0

At a glance

What is it?
HMA-OSS is a fork of Hide My Applist that replaces the LSPosed dependency with Zygisk, so app-list hiding runs inside the Zygisk injection path on a rooted device. It is aimed at people who already run Magisk with Zygisk enabled and want per-app control over which packages another app can see.
Who is it for?
Adopt HMA-OSS if you already run Magisk with Zygisk enabled, you are comfortable with a root-level module that changes what other apps can observe, and you want the Hide My Applist feature set without an LSPosed dependency. Do not adopt it if your device is not rooted, if you are not willing to keep a module updated alongside Magisk and your Android version, or if you only need to block a single permission and would rather not touch the injection path.
Can I use it commercially?
Yes, with strict conditions. AGPL-3.0 is a network copyleft licence: if people use a modified version over a network, for example as a hosted service, you must offer them its source code under the same licence.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly Kotlin, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The fingerprinting problem HMA-OSS addresses

Android lets an app query which other packages are installed. That is normally harmless, but the README points at two ways it gets abused. The first is root detection by proxy: not every root-related app randomizes its package name, so an app that sees Fake Location or Storage Isolation in the package list can infer the device is rooted even without a direct root check. The second is broader: the README describes apps using "various loopholes" to acquire your app list and treat it as fingerprinting data. HMA-OSS exists to break both signals by controlling what the querying app receives.

The target user is someone who already has a rooted device and wants to keep specific apps invisible to specific other apps. This is not a privacy tool for unrooted phones, and it is not a general permission manager. The repository topics list requires-root and zygisk-module, which sets the floor: without root and Zygisk, nothing here runs.

How the Zygisk fork differs from the original Hide My Applist

The project describes itself as a fork of Hide My Applist in which the LSPosed dependency is replaced with Zygisk. That single substitution changes where the code lives. LSPosed hooks methods inside a running process through its own framework; Zygisk injects into the app process at startup from Magisk. The repository layout reflects this: there are separate top-level directories named app, common, stub, and zygote, plus an external directory, alongside a Gradle build using build.gradle.kts and settings.gradle.kts. The zygote directory is the part that does the injection work, and the app directory is the Android application that provides the configuration interface.

For the user, the practical difference is the dependency chain. An LSPosed module requires the LSPosed framework to be installed and the module to be enabled inside it. A Zygisk module requires Magisk with Zygisk enabled and is enabled through Magisk's module list. That is why the project carries the formerly-lsposed-module topic: it is the same feature set, moved onto a different injection mechanism. If you are migrating from the original, the configuration surface is the part you should expect to relearn, since the module no longer appears in LSPosed's scope list.

Installing HMA-OSS and getting it to activate

The README does not contain a step-by-step install guide. It points to a wiki at the project's GitHub wiki for HMA-OSS details, and the repository ships a fastlane directory, which is the standard layout for distributing the companion APK. Because the README is silent on exact install commands, treat the wiki as the authoritative source and do not follow instructions written for the original LSPosed-based Hide My Applist.

What can be stated from the repository structure is the shape of the install: a Zygisk module plus an app. The module side is what Magisk loads, and the app side is what you open to configure it. The repository is a Gradle project whose build entry points are the wrapper scripts gradlew and gradlew.bat, driven by settings.gradle.kts and build.gradle.kts, so any build from source goes through the Gradle wrapper rather than a hand-written toolchain command.

After the module is in place, reboot so Zygisk can inject into app processes, then open the HMA-OSS app to choose which apps are hidden from which observers. The configuration is the part the wiki covers, and the project also links a Crowdin project for translations, which tells you the app has a localized interface rather than a command-line one.

The most common activation failure is that Zygisk itself is off. The module cannot do anything if Magisk is not injecting, so check that Zygisk is enabled in Magisk's settings before concluding the module is broken.

What the repository does not tell you

The README is short and mostly points outward. It does not document rollback, it does not list supported Android versions, and it does not describe the configuration file format. The Update log section is a pointer to the commits page rather than a changelog, so release notes live in the releases themselves: oss-168, oss-166, and oss-164 are the recent tags, dated 2026-09-13, 2026-08-09, and 2026-07-10 respectively. Anyone who needs to know what changed between two builds has to read commits.

That thinness matters for a module that sits in the injection path. A Zygisk module runs inside every app process it targets, so a bug is not confined to one screen. The project is licensed AGPL-3.0, and the LICENSE.md file is at the repository root. If you plan to redistribute a modified build, the licence terms are the thing to read, not this article. There is no homepage field on the repository, so the GitHub wiki and the linked Telegram channel are the only support channels the README names.

When HMA-OSS is the wrong tool

If your device is not rooted, stop here. Every mechanism in this project depends on Zygisk, which depends on Magisk, which depends on root. There is no non-root mode and the README does not suggest one.

A second case is narrower than it looks. Hiding an app from another app's package query is not the same as hiding the app's presence from the filesystem, from a shared storage scan, or from a network request. If the observer uses a detection path other than the package list, HMA-OSS does not claim to cover it. The README frames the problem as app-list acquisition and root detection by proxy, and that is the scope.

A third case is stability preference. A module in the injection path is one more thing that can interact badly with an Android update, with another Zygisk module, or with an app that does its own integrity checks. If you want a device you never have to debug, this class of tool is a poor fit regardless of which fork you pick.

Alternatives and how they differ

The obvious alternative is the original Hide My Applist running under LSPosed. The two share a lineage, since HMA-OSS is a fork of it, but the runtime is different: the original needs the LSPosed framework installed and the module scoped inside it, while HMA-OSS needs Magisk with Zygisk. If you already run LSPosed for other modules, the original keeps everything in one management UI. If you run Zygisk but not LSPosed, HMA-OSS removes a framework from your stack. That is the whole trade, and it is a real one: fewer moving parts versus a different management surface.

A second comparison point is doing nothing and accepting the exposure. Root-hiding and app-list-hiding serve different goals, and a user who only cares about one specific app's behaviour may find that a per-app permission change or simply not installing the root app in question solves the problem without a module at all. The README's own framing supports this: it notes that not every root app supports random package names, which is a statement about the ecosystem, not a claim that HMA-OSS is the only remedy.

Maintenance, updates and licence

The last push to the repository was on 2026-09-22, and the most recent release tag is oss-168 from 2026-09-13. The repository is not archived. Releases appear at roughly monthly intervals based on the three recent tags, though three data points do not establish a schedule.

The upgrade cost is the usual one for Zygisk modules: a new release means reinstalling the module and rebooting, and the app side may need updating in step with it. Because the README does not document rollback, keep the previous release zip before upgrading so you can revert if a build misbehaves. The AGPL-3.0 licence applies to the source; if you only install releases for personal use, the practical obligation is minimal, but redistributing a modified build carries source-disclosure requirements. That is a description of the licence, not legal advice.

Editorial conclusion

Adopt HMA-OSS if you already run Magisk with Zygisk enabled, you are comfortable with a root-level module that changes what other apps can observe, and you want the Hide My Applist feature set without an LSPosed dependency. Do not adopt it if your device is not rooted, if you are not willing to keep a module updated alongside Magisk and your Android version, or if you only need to block a single permission and would rather not touch the injection path. Before installing, verify that Zygisk is actually enabled in your Magisk settings, because the module cannot activate without it, and check the wiki linked from the README for the current configuration steps rather than relying on older Hide My Applist guides.

Frequently asked questions

My HMA-OSS module isn't activated. How can I fix this?

The module runs through Zygisk, so the first thing to confirm is that Zygisk is enabled in Magisk. If it is enabled and the module still does not activate, check the project wiki, which the README names as the place for HMA-OSS details.

How to install HMA-OSS?

The README does not give install steps and instead points to the project wiki. The repository ships a fastlane directory for the companion app and the module is installed as a Zygisk module through Magisk, followed by a reboot.

What is HMA-OSS?

It is a Zygisk module that hides your app list, settings, and package installers from other apps. It is a fork of the Hide My Applist project in which the LSPosed dependency is replaced with Zygisk.

How does HMA-OSS differ from the original HMA?

HMA-OSS is a fork of Hide My Applist that swaps LSPosed for Zygisk. That means it is enabled through Magisk with Zygisk rather than scoped inside the LSPosed framework, which is why the repository carries the formerly-lsposed-module topic.

What is the HMA-OSS configuration?

Configuration happens in the companion app, which is what the app directory in the repository builds. The README does not document the configuration file format and directs readers to the wiki instead.

Official sources

  1. frknkrc44/HMA-OSS on GitHub
  2. Issues
  3. License: AGPL-3.0
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/frknkrc44-hma-oss.svg)](https://hysenlabs.com/projects/frknkrc44-hma-oss)