SmartTube YouTube app for Android TV breached to push malicious update
ID: 25db91a6-6259-58a0-a517-090cd0da82d8
STIX ID: report--25db91a6-6259-58a0-a517-090cd0da82d8
Feed Name: Bleeping Computer
The SmartTube Android TV client was compromised after the developer's signing keys and development environment were breached, allowing a hidden native library (libalphasdk.so) to be injected into release APKs (reported around versions 30.43–30.47). The library silently fingerprints devices, registers them with a remote backend and exchanges encrypted configuration; while there is no confirmed account theft or botnet activity, the supply‑chain compromise poses a high risk. The developer has revoked the old signature and plans a new app build with a new key and app ID; users are advised to avoid affected versions, disable auto‑updates, and reset credentials until a transparent post‑mortem is published.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
