https://blog.thereallo.dev/blog/decompiling-the-white-house-app
Wowy wow wow wow! I’m sure none of y’all planned on downloading the malware from the Mango, but just in case, DO NOT. It will:
Inject JavaScript into every website you open
Has a full GPS tracking pipeline always on.
Loads JavaScript from a random person's GitHub Pages site (lonelycpp.github.io) for YouTube embeds.
Loads third-party JavaScript from Elfsight (elfsightcdn.com/platform.js) for social media widgets, with no sandboxing.
Sends email addresses to Mailchimp, images are served from Uploadcare, and a Truth Social embed is hardcoded with static CDN URLs. None of this is government infrastructure.
Has no certificate pinning.
Ships with dev artifacts in production.
Profiles users extensively through OneSignal - tags, SMS numbers, cross-device aliases, outcome tracking, notification interaction logging, in-app message click tracking, and full user state observation

