logo

AppsFlyer Web SDK hijacked to spread crypto-stealing JavaScript code

ID: fec72399-adfc-5acf-a669-d4ca2f1f8649

STIX ID: report--fec72399-adfc-5acf-a669-d4ca2f1f8649

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-03-14

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive summary:** The AppsFlyer Web SDK was briefly hijacked (estimated March 9–11, 2026) to deliver obfuscated JavaScript that hooks browser network requests, monitors cryptocurrency wallet inputs (Bitcoin, Ethereum, Solana, Ripple, TRON), replaces them with attacker-controlled addresses to divert funds, and exfiltrates the original addresses and metadata; Profero researchers discovered the payload, AppsFlyer acknowledged a domain registrar incident and containment, and impacted organizations are advised to review telemetry, revert to known-good SDK versions, and investigate potential compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.