AppsFlyer SDK Exploited in New Supply Chain Crypto Attack
ID: f2e8352c-7679-5fd6-a205-7d1ebd473ee5
STIX ID: report--f2e8352c-7679-5fd6-a205-7d1ebd473ee5
Feed Name: Security Boulevard
Threat Score
Between March 9–11, 2026, attackers compromised the AppsFlyer Web SDK on AppsFlyer’s CDN, injecting obfuscated JavaScript that intercepted cryptocurrency wallet addresses entered by users, swapped them for attacker-controlled addresses, and exfiltrated metadata; the malicious code continued legitimate analytics functions to avoid detection, exposing a large number of websites and users for approximately 48 hours.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
