logo

AppsFlyer SDK Exploited in New Supply Chain Crypto Attack

ID: f2e8352c-7679-5fd6-a205-7d1ebd473ee5

STIX ID: report--f2e8352c-7679-5fd6-a205-7d1ebd473ee5

Feed Name: Security Boulevard

Threat Score
85/100

Date Published: 2026-04-07

Date Updated: 2026-04-22

Author: Onn Nir

...
...

Between March 9–11, 2026, attackers compromised the AppsFlyer Web SDK on AppsFlyer’s CDN, injecting obfuscated JavaScript that intercepted cryptocurrency wallet addresses entered by users, swapped them for attacker-controlled addresses, and exfiltrated metadata; the malicious code continued legitimate analytics functions to avoid detection, exposing a large number of websites and users for approximately 48 hours.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.