AppsFlyer Web SDK hijacked to spread crypto-stealing JavaScript code
ID: fec72399-adfc-5acf-a669-d4ca2f1f8649
STIX ID: report--fec72399-adfc-5acf-a669-d4ca2f1f8649
Feed Name: Bleeping Computer
**Executive summary:** The AppsFlyer Web SDK was briefly hijacked (estimated March 9–11, 2026) to deliver obfuscated JavaScript that hooks browser network requests, monitors cryptocurrency wallet inputs (Bitcoin, Ethereum, Solana, Ripple, TRON), replaces them with attacker-controlled addresses to divert funds, and exfiltrates the original addresses and metadata; Profero researchers discovered the payload, AppsFlyer acknowledged a domain registrar incident and containment, and impacted organizations are advised to review telemetry, revert to known-good SDK versions, and investigate potential compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
