v0.0.10
HushThreads v0.0.10 has 10 patches for Threads 449.0.0.54.82 (com.instagram.barcelona), and it works with Threads 448.0.0.54.85 too. It's built on Morphe patcher 1.15.0, so update Morphe Manager to 1.33.0 or newer before you patch. This release carries everything from the 0.0.5 to 0.0.10 source builds.
Threads
- HushThreads now builds on Morphe patcher 1.15.0, so it needs Morphe Manager 1.33.0 or newer. Manager 1.32.0 asks for an update before it loads the bundle.
- The README explains how safe mode and Threads' own crash protection fit together. Five quick crashes within four hours make Threads delete its data, and safe mode steps in after three, so it gets there first. It also says which crashes Pause can't stop and what to do about them.
- A Galaxy S23 Ultra running Threads 449 with HushThreads 0.0.4 confirmed that Hide suggested users takes the live Suggested Users block out of the feed.
- The overview, About and support reports identify the exact packaged bundle, including its payload hash and clean, modified or unknown source state. Identical repacks keep the same identity. Missing or damaged current metadata remains unverified.
- The overview keeps the full payload hash with a compact source state. About and exports retain the complete source record. At large text sizes, Pause, Resume and Undo appear above the summary so build details can't push recovery off the screen.
- The settings overview names any default patches omitted from a build. Diagnostic exports include the app's declared web domains and Android's current link selections, with an explicit unavailable state on older versions.
- Diagnostic exports redact filesystem paths from buffered events and saved Java/native crashes, including quoted paths with spaces, escaped forms and file URLs. Stack-trace filenames, package names and current signing-certificate hashes remain useful.
- Support reports label the HushThreads bundle explicitly and include bounded hashes of the installed app's current signing certificates and available installer details. Android 9 uses the legacy installer API. Missing facts and query failures remain explicit. No certificate contents, signing keys or other apps' details are exported. Add your Manager version and install method when you send one.
- Release checks use a separate TLS connection that sends no cookies and leaves Threads' shared cookie handler and store untouched. Response cookies are discarded. GitHub host checks, opt-in behavior, Pause, redirect limits and bounded responses still apply.
- If you patch Instagram with HushGram using the same Morphe Manager signing key, Threads now shows your Instagram account as a tile on its login screen, and tapping it signs you in without a password. Restore screens on re-signed builds checks the exact package, that it's a separate app and its installed certificate first, so apps signed with other keys still get Threads' usual answer. Checked on Android 17 with Threads 449 and HushGram 0.0.4.
- The bug report form includes Shizuku installs. The sign-in guide corrects the Android 17 report's install method and records successful settings-only and full-bundle password checks with Shizuku's installer identity and session options.
- Hide ads and Hide suggested users diagnostics count successfully checked feed pages and items, even when Threads sends nothing to remove. Disabled, paused and failed checks don't count. Removal counts still record only items taken out of a completed page.
Tooling
- smali now matches the commit patcher 1.15.0 asks for. The old pin was one commit behind it but sorted higher, so Gradle had been compiling and testing against the older dexlib2. The fixture gates move to desktop CLI 1.18.0.
- The localization guard also catches a settings row built through a qualified
HushThreadsPreferenceFragmentcall in another source file. Before, it only looked for the row helpers inside the fragment itself, so an untranslated title elsewhere passed. - A fixture test reads Threads' crash-loop thresholds out of each declared build and fails if safe mode would wait as long as Threads' data wipe, or if it counts fewer seconds after a start than Threads does.
- Bundle and receipt checks verify the packaged identity before accepting source claims. Existing display tests expected version-only text and placed recovery below the summary, which could hide it behind the new build details. Assertions now cover the payload field and accessible action placement, alongside tampering, archive, loaded-bundle and export checks.
- Shared fixes and the Turkish GitHub wording correction are ported with per-file provenance. Tests cover missing defaults, Unicode domains and both report exports. An older analytics test expected only one report line and missed the new default-selection disclosure. Its analytics assertions remain intact. Android 9 also exercises the saved-file report through its actual legacy destination.
- Clipboard and saved-file tests cover every diagnostic section on Android 9, 11 and 16 with Debug logging on and off. The earlier tests only checked request addresses and credentials. Long quoted values now avoid regex stack overflow, and the Windows file-write fixture only uses the new-file field on Android versions that have it.
- Package-specific advisory ratings now follow OSV's listed-version/range union with Maven version ordering. Introduced, fixed, last-affected and limit boundaries are checked across unsorted intervals. Known nonmatching ranges no longer cause a false hold, and unreadable range metadata requires review. Previous package tests covered listed versions but never excluded an unaffected range.
- Advisory objects and rating fields are checked before reading them. Arrays in scalar fields and nested severity/affected arrays require review, including package metadata without optional severity. Query containers, IDs, aliases, summaries and page tokens keep their JSON types and UTF-8 values. Malformed withdrawals stop the check instead of discarding an advisory. Valid UTC timestamp strings work on PowerShell 7.5+ and Windows PowerShell 5.1. Supported HIGH/CRITICAL ratings remain visible. Earlier fixtures missed shapes PowerShell could coerce or silently skip.
- Release checks include OSV's package-specific severity for the queried library, including ecosystem-wide ratings. Unrelated packages and entries listing only other versions are excluded. Malformed or unsupported ratings still require review. Previous tests used advisory-wide vectors and missed a package-specific HIGH rating hidden by a LOW database label.
- The release-check deadline covers name resolution, TLS handshakes and request writes as well as response reads. A stalled resolver leaves bounded background work, and expired waiting requests are removed. Earlier transport tests checked body reads but missed slow connection phases. Thirteen transport checks pass on native Android 9 and 17, and both platforms read the live release endpoint with the shared cookie store unchanged.
- Explicit null severity entries and malformed non-array severity fields require advisory review. A missing optional field or a valid empty array stays distinct. Existing tests covered unreadable vectors but missed null entries that the pipeline silently removed.
- Support-report tests now exercise Android 9 and newer install-source APIs, current versus past certificates, missing or excessive signer data and unsafe source names through the exports. The previous version assertion accepted the misleading morphe label and didn't check these installation facts. The reporting guide also clarifies Android 9's saved-file location.
- The release advisory gate holds unsupported or malformed severity data for review even beside a lower label or score. CVSS 4 findings can no longer pass under LOW/MODERATE labels. Supported HIGH/CRITICAL ratings remain visible. CVSS 3 vectors with duplicate metrics or invalid optional values are refused as unreadable instead of receiving a score.
- Release transport tests capture the transmitted request, including changing and header-dependent cookie handlers. The old preflight test required deleting shared GitHub cookies, which contradicted preserving the store. Nine wire tests pass on native Android 9 and 17, and both platforms read the live release endpoint with their normal TLS trust and hostname checks.
- The build's source guard parses Kotlin and Java import declarations to catch direct Guava imports with legal whitespace, comments, aliases or static imports. Examples in strings and comments, similar package names and an infix function named import remain allowed. The parsers are test dependencies and aren't included in the patch bundle.
Update
- You need Morphe Manager 1.33.0 or newer. Manager 1.32.0 asks for an update before it loads this bundle. If HushThreads is already one of your patch sources, Manager shows 0.0.10 once it refreshes. If it isn't, add it: https://morphe.software/add-source?github=SysAdminDoc%2FHushThreads
- Patch the arm64-v8a bundle of Threads 449.0.0.54.82 (version code 511908382) or 448.0.0.54.85 (version code 511808302).
- Patch with the Morphe Manager signing key you used last time. That's what lets the update install over your patched Threads and keep your data. Coming from the stock Threads, uninstall it first.
- Sign in with your Instagram username and password. If you patch Instagram with HushGram using the same signing key, you can tap your Instagram account on Threads' login screen instead.
The .mpp download is a patch bundle, not a Threads APK. Installation instructions.
Validation
513 runtime tests and 183 patch tests passed locally, along with both Android lints and the release script checks. All 10 patches applied without forcing to Threads 449.0.0.54.82 and 448.0.0.54.85, and the release receipt records both runs. The dependency advisory check passed.