logo

SmartTube YouTube App for Android TV Compromised Following Exposure of Signing Keys

ID: 1caead0a-b4a7-5ed9-bb22-11da86bd95c7

STIX ID: report--1caead0a-b4a7-5ed9-bb22-11da86bd95c7

Feed Name: cybersecurityNews.com

Threat Score
82/100

Date Published: 2025-12-02

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

SmartTube, a popular third-party YouTube client for Android TV, was compromised after the developer's signing key was exposed; attackers injected malicious native libraries (libalphasdk.so / libnativesdk.so) into official releases and in-app updates, which perform device fingerprinting, persistent background surveillance, and covert C2 over Google services—Google Play Protect flagged and disabled infected installs (noted infected versions 30.43–30.55).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.