logo

SmartTube YouTube app for Android TV breached to push malicious update

ID: 25db91a6-6259-58a0-a517-090cd0da82d8

STIX ID: report--25db91a6-6259-58a0-a517-090cd0da82d8

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-12-01

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

The SmartTube Android TV client was compromised after the developer's signing keys and development environment were breached, allowing a hidden native library (libalphasdk.so) to be injected into release APKs (reported around versions 30.43–30.47). The library silently fingerprints devices, registers them with a remote backend and exchanges encrypted configuration; while there is no confirmed account theft or botnet activity, the supply‑chain compromise poses a high risk. The developer has revoked the old signature and plans a new app build with a new key and app ID; users are advised to avoid affected versions, disable auto‑updates, and reset credentials until a transparent post‑mortem is published.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.