Back to Feed
Supply ChainMar 14, 2026

AppsFlyer Web SDK hijacked to spread crypto-stealing JavaScript code

AppsFlyer's Web SDK was compromised in a supply-chain attack that injected malicious JavaScript code designed to steal cryptocurrency from users. The hijacked SDK affected downstream applications that integrated the legitimate library, making this a significant supply-chain security incident.

Summary

AppsFlyer's Web SDK was compromised in a supply-chain attack that injected malicious JavaScript code designed to steal cryptocurrency from users. The hijacked SDK affected downstream applications that integrated the legitimate library, making this a significant supply-chain security incident.

Indicators of Compromise

  • malware — AppsFlyer Web SDK (malicious variant)