SmartTube YouTube App for Android TV Compromised Following Exposure of Signing Keys
ID: 1caead0a-b4a7-5ed9-bb22-11da86bd95c7
STIX ID: report--1caead0a-b4a7-5ed9-bb22-11da86bd95c7
Feed Name: cybersecurityNews.com
Threat Score
SmartTube, a popular third-party YouTube client for Android TV, was compromised after the developer's signing key was exposed; attackers injected malicious native libraries (libalphasdk.so / libnativesdk.so) into official releases and in-app updates, which perform device fingerprinting, persistent background surveillance, and covert C2 over Google services—Google Play Protect flagged and disabled infected installs (noted infected versions 30.43–30.55).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
