Supply ChainMar 14, 2026
AppsFlyer Web SDK hijacked to spread crypto-stealing JavaScript code
AppsFlyer's Web SDK was compromised in a supply-chain attack that injected malicious JavaScript code designed to steal cryptocurrency from users. The hijacked SDK affected downstream applications that integrated the legitimate library, making this a significant supply-chain security incident.
Summary
AppsFlyer's Web SDK was compromised in a supply-chain attack that injected malicious JavaScript code designed to steal cryptocurrency from users. The hijacked SDK affected downstream applications that integrated the legitimate library, making this a significant supply-chain security incident.
Indicators of Compromise
- malware — AppsFlyer Web SDK (malicious variant)