Plus Messenger is a fork of Telegram for Android with over 50 million Google Play installs. Telegram’s Android code is GPL-2.0-or-later. The fork hasn’t published a line of source since September 2017, and its current release carries an advertising and billing layer that exists in no public repository. Everything below links to something you can open and check yourself.

The published source stopped in 2017

The developer’s GitLab project holds three commits and no tags. You can verify that in a browser right now:

0978c068  2017-09-13  Add readme.md
1d961518  2017-09-13  Update to v4.2.1.1     (the last code commit, ever)
b418c867  2019-02-07  Update README.md       (documentation only)

https://gitlab.com/api/v4/projects/4142452/repository/commits

Its build.gradle carries versionCode 1047. The current Play release is 12.10.1.0, dated 2026-08-29. Two source requests citing the licence have sat open on that tracker since October 2018.

The shipped binary contains code that appears in no published source

Release 12.10.1.0, obtained 2026-09-01 and checked with apksigner:

base APK SHA-256  d332a1304fc0c0c3daecc8fe7321893f7a6e88ffb59916743d175bf626fbbfef
V3 signer cert    6ebb622268aad319dbe8a1f414837d2843a9b35856aefb7dee2971a3d493f276
signature schemes v1 + v2 + v3: verified

The signer certificate is the developer’s own, so this is his build. Inside: current upstream Telegram GPL code, including 2026 features, plus a proprietary layer under org.telegram.plus with ads.AdsController, ads.BillingHelper, helpers.FirebaseHelper and ads.RemoveAdsBottomSheet, bundled with AdMob, Firebase Analytics and the Play billing client. The purchase sheet sells ad removal for 5.99 euros and donation tiers up to 99.99. There is no licence text, no written offer and no source link anywhere in the app. In the published repositories the path org/telegram/plus returns HTTP 404.

The stated reason now describes the developer

The support group’s pinned rules, in place since 2019, say the source is withheld to stop third-party developers “using the code for their own benefit by adding advertising”, and that the group is not the place to ask about source code. On 2025-10-02 the developer announced advertising and a paid removal himself. Eight months later the group’s automated responder was still telling users the app “is not a commercial project”.

What happened when this was reported

I posted the record on the F-Droid forum on 1 September. At 03:47 UTC the next morning the forum deleted my account, citing no rule, with the topic still sitting in the new-user moderation queue. Two minutes later, at 03:49, a person whose F-Droid forum title reads “Contributor, F-Droid Board Member” turned up on the Telegram-FOSS tracker on GitHub under my comment there and wrote: “please delete this comment from the bot above. The bot has come and posted on several forums. Just created account and posted this. Banned them. Reporting this as well.”

https://github.com/Telegram-FOSS-Team/Telegram-FOSS/issues/377#issuecomment-5504070601

I asked F-Droid about it on their own admin tracker, which is where their Code of Conduct sends complaints. The issue was closed 80 seconds after my reply with “ah, ok then”, followed by “I would have deleted your post and account too”. A second issue, about the board member specifically, was closed as a duplicate with no comment on it at all.

https://gitlab.com/fdroid/admin/-/issues/700

The “off-topic” defence has a hole in it. The developer submitted this exact app to the F-Droid forum in March 2015, describing it in his own words as “GNU GPL v2”, and a moderator declined it for bundling play-services. That thread is still up: https://f-droid.org/forums/topic/plus/

Where it stands

Telegram, the copyright holder and the only party that can force a store takedown, has been notified twice and hasn’t replied. Its GitHub repository has issues disabled. Google Play’s public intellectual-property form refuses the category outright, leaving only the rights-holder DMCA form. The FSF Compliance Lab, the Software Freedom Conservancy, FSFE and the Software Freedom Law Center have the file. A formal section 3 source request sits unanswered on the developer’s own tracker: https://gitlab.com/rafalense/plus-messenger/-/issues/84

Full write-up with every hash and citation: https://xdaforums.com/t/plus-messenger-9-years-of-telegram-gpl-code-with-no-source-now-with-an-unpublished-paid-ads-layer.4800334/

I’m one person, writing under a pseudonym because the same developer also made WhatsApp Plus and I’d rather he never learned my name. That new account is what got me called a bot. If the source is published, I’ll say so.

  • AbsolutelyNotCats@lemdro.idOP
    link
    fedilink
    English
    arrow-up
    8
    ·
    3 days ago

    Update: the XDA thread is locked. A moderator closed it as “obviously a rant about something that occurred outside of XDA Forums”, after stripping about thirty of the primary-source links out of the post. The F-Droid forum deleted my account before my post there was ever approved.

    So the write-up now lives where nobody can lock or edit it, and I’ll keep it updated there: https://opensource-compliance-gh.github.io/plus-messenger-gpl/

    Commit log, APK hashes, the dex inventory of the unpublished org.telegram.plus package, the pinned “don’t ask for source” rules going back to 2016, the Huawei AppGallery listing, the moderation timeline, and a chapter that walks you through checking all of it yourself in about ten minutes. Every claim links to something you can open.

  • hexagonwin@lemmy.today
    link
    fedilink
    English
    arrow-up
    10
    ·
    3 days ago

    for some reason there’s so many sketchy telegram clients. nekogram which was once on f-droid was also found including some malware/backdoor shits.

    • rotten@lemmy.today
      link
      fedilink
      arrow-up
      1
      ·
      2 days ago

      Unfortunately it’s so hard to find good TG client recently. I’ve been using Nekogram too and it’s been my favourite client aswell until someone found, that developers embedded hidden Java script that extracted phone number from your accounts, that you were logged into and sent them to OSINT bot. Also I can’t recall Nekogram ever being on F-Droid, you must’ve been thinking about Nekogram X which is gone for a long time.

      There’s also AyuGram (quite popular TOS breaking TG client), which last commit on their GitHub page was like 4 years ago (if Nekogram extracted your phone number then one can only think what kind of shit AyuGram is extracting/doing on your phone😂)

      I think the safest option would probably be “Fork Client”, or if you dont mind having less features Telegram FOSS. What I think I will do is either having Forkgram Classic or Fork Client or Telegram FOSS with some LSPosed modules that add some functionalities like speed boost or saving restricted content etc.

      • hexagonwin@lemmy.today
        link
        fedilink
        arrow-up
        2
        ·
        2 days ago

        i’m actually still using ‘Telegram FOSS’ lol. i installed it years ago, it still seems to work so i have no reason to switch.

        have ‘Telegram X’ on my other phone and it’s pretty neat, but it doesn’t handle groups with multiple channels inside.

  • bizdelnick@lemmy.ml
    link
    fedilink
    arrow-up
    5
    arrow-down
    2
    ·
    3 days ago

    Why you suppose that necroposting in unreladed projects’ forums and issue trackers is the right way to report a licensing issue?

    • AbsolutelyNotCats@lemdro.idOP
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 days ago

      Good question. Shame about the facts.

      The licence report went where licence reports go: an issue on the developer’s own GitLab repo (#84, sitting next to #20 and #22, both unanswered), plus the FSF, Software Freedom Conservancy, Telegram and Huawei by email. None of that is a forum.

      The F-Droid forum is a discussion forum for free software, where people argue about licences every day. A GPL-2.0 fork with 50M+ Play installs, no published source since 2017 and a paid ad layer that appears in no repository isn’t off-topic there. It’s the whole subject of the room.

      And my topic never went live anyway. Staff deleted my account before any moderator approved it. Two minutes after that deletion, an F-Droid board member showed up on a different project’s GitHub tracker, called my report a bot, asked for it to be deleted, and wrote “Banned them. Reporting this as well.” He followed the report to another site to get it removed there too. That’s what the fdroid/admin issues are about. Not the licence. The deletion, and him.

      Which leaves one comment on Telegram-FOSS 377, the only public thread about this app anywhere in a Telegram-fork community. Ten years of this, one comment.

      Several people have now told me where I should have posted. Not one has told me which line is wrong. No hash, no commit date, no sentence of GPLv2 section 3 has been touched.

      Want more data? All of it is here, every claim linked to something you can open yourself: https://opensource-compliance-gh.github.io/plus-messenger-gpl/

      • redjard@reddthat.com
        link
        fedilink
        arrow-up
        4
        arrow-down
        10
        ·
        3 days ago

        Not irrelevant at all. For one it’s something you should declare at a minimum, not doing so seems dishonest to me, especially on a foss community.

        I checked and it’s not just my impression, the “baseline ai detector” pangram also flags you reliably in all parts I tried for example (even more than me, I only get the impression from some paragraphs). So I would like to know why you use very ai-like phrases and formatting if this isn’ tai.

        Also, sounding like ai is a valid explanation for a lot of the treatment you described. You call yourself “opensource-compliance-gh”, and revive a 6 year old github issue, by posting a lengthy text about legal stuff and morals that sounds like ai.

        And, if this is not ai, then sounding like it is a massive sign of ai psychosis, which would mean any facts you reference are suspect by default. “AI voice” is a sign of untrustworthiness, and for good reason.


        As for the actual post, have you actually made sure you understand the legal situation? Have you tried finding out from the devs if there is a special licensing going on? Have you checked for CLAs (do you even know what that is)?

        PS: “Irrelevant. Stick to the topic.” is how you talk to an ai, not a person. You don’t command prople like that, it’s at best extremely unfriendly.

        • AbsolutelyNotCats@lemdro.idOP
          link
          fedilink
          English
          arrow-up
          4
          arrow-down
          1
          ·
          2 days ago

          Impressive work. You ran a classifier on a stranger’s paragraphs, compared the score to your own, and diagnosed a mental illness from sentence rhythm. Write it up. Pangram-based deception screening is a real growth area, and HR departments will pay for exactly that skill. You’d be sorting CVs by em dash density inside a week.

          Meanwhile: no, I don’t use AI. I think it’s trash. I read 305,000 Telegram messages, decompiled an APK and wrote it up like a report because that’s what it is. If writing in full sentences makes me a psycho, fine, I’m a psycho with a hash table.

          A SHA-256 doesn’t change depending on who typed it. I built the dossier out of commit ids, signer certs, dex listings and timestamped messages for that reason, instead of adjectives. Three commits on rafalense/plus-messenger, last code commit 2017-09-13, straight from the GitLab API. An org/telegram/plus package in the shipping APK that appears in no published source. None of that needs my credibility, or my prose style, to stand up.

          Now the two questions you asked as if they were checkmate, both answered in the document before you showed up.

          CLAs run the other way round. Contributors sign one with Telegram so Telegram can relicense their work. It hands a downstream fork author nothing. rafalense isn’t upstream, he’s a recipient of Telegram’s GPL-2.0 code, same as you.

          Special licensing is chapter 11, where I wrote, unprompted, that a private grant from the rights holders is the strongest defence he has, that nothing public suggests one exists, and that if one does, one sentence from him ends this faster than publishing the source would. People have asked since 2016. Ten years, no sentence. What his repos do carry is a GPLv2 LICENSE file, he submitted the app himself as “GNU GPL v2”, and his group’s pinned rules argue about the source in licence terms instead of pointing at a private deal. I wrote his best defence for him. You didn’t read it, but you did run a detector on it.

          The six-year-old issue is titled “Implement Plus Messenger Features” and it’s the only public thread about this app in any Telegram-fork community. Open a new one and it’s spam. Reply in the old one and it’s necroposting. Convenient system.

          As for “Irrelevant. Stick to the topic” being how you talk to an AI: you asked me whether I was a robot, then called my evidence untrustworthy because a detector didn’t like the paragraphs. That reply was the friendly version.

          • redjard@reddthat.com
            link
            fedilink
            arrow-up
            3
            ·
            2 days ago

            You ran a classifier on a stranger’s paragraphs, compared the score to your own, and diagnosed a mental illness from sentence rhythm.

            I felt something might be off, and asked. Got a hostile and weird response, and only then ran a classifier to have something that’s not just my own judgement. Of course this isn’t perfect.
            I also don’t claim you have ai psychosis, I explained why I care if you sound like ai or use ai.

            If writing in full sentences …

            It was a few specific phrases and the style of headers. “The “off-topic” defence has a hole in it.”, “What happened when this was reported”, “Three things to take from that” (from xda). Things like that.

            I wrote his best defence for him. You didn’t read it, but you did run a detector on it.

            I checked the last paragraphs of your post here on lemmy (which I read in entirety), nothing more. I didn’t read the xda post when I wasn’t sure this was worth spending more time on.
            I have now read it, I don’t see you mention the potential of a private agreement there either.

            Now the two questions you asked as if they were checkmate, both answered in the document before you showed up.

            Not sure which document you mean. But I asked to make sure you know what you are talking about (and because I was missing that info), and your answer makes sense, so that’s fine. That’s why I asked.
            󠀀
            󠀀
            Anyway, so the plus “fork” could have a private agreement, and telegram would fully legally be allowed to do that since they own all contributions? And at the same time contributers can’t sue, only telegram can, if the “fork” doesn’t have an agreement? Meaning either way Telegram lets this happen?

            As for downstream by itself, I don’t see any legal problem. If the “fork” dev wants to no longer publish code and only publishes 3 documents of text, that’s fully in their right. You can keep copies of the old code, but if there are no upstream requirements then nothing in gpl forces code to stay online. As code owner you can always make a closed fork.
            (That’s why software on gpl but with CLAs that sign over contributor’s rights, or software that doesn’t accept contributions, is fake foss. But that’s a different topic)

            I’d then say Telegram have a free “foss” branch and a paid closed branch based on it, which is a common business model for “foss” software companies.
            With the difference that Telegram obfuscates that by making the monetized project publicly separate, and would now potentially be hiding that fact by censoring discussion?