CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Cryptocurrency Stealer via AppsFlyer Web SDK

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Malicious JavaScript code delivered through the AppsFlyer Web SDK intercepted cryptocurrency wallet addresses on websites, replacing them with attacker-controlled addresses to divert funds. The payload was served from the official domain 'websdk.appsflyer.com' and targeted Bitcoin, Ethereum, Solana, Ripple, and TRON addresses. The incident impacted thousands of applications and end users, with the exposure window likely between March 9 and March 11, 2026. AppsFlyer confirmed unauthorized code delivery but stated the mobile SDK was unaffected and the issue has been resolved.

Timeline

  1. 14.03.2026 16:36 1 articles · 5h ago

    Malicious JavaScript Delivered via AppsFlyer Web SDK

    On March 9, 2026, Profero researchers discovered a malicious payload served by the AppsFlyer Web SDK from its official domain, 'websdk.appsflyer.com.' The payload intercepted cryptocurrency wallet addresses and replaced them with attacker-controlled addresses. The exposure window is suspected to be between March 9, 22:45 UTC, and March 11, 2026. AppsFlyer confirmed unauthorized code delivery but stated the mobile SDK was unaffected and the issue has been resolved.

    Show sources

Information Snippets