Threats & Adversaries · Supply Chain
AppsFlyer's Web SDK briefly served obfuscated JavaScript that targeted cryptocurrency wallet fields. The code replaced entered wallet addresses with attacker-controlled addresses and exfiltrated originals.
1 source · Mar 14
BleepingComputer
AppsFlyer Web SDK hijacked to spread crypto-stealing JavaScript code
The AppsFlyer Web SDK was temporarily hijacked this week with malicious code used to steal cryptocurrency in a supply-chain attack.
originalPart of the PlainSec briefing for 2026-03-15
Every edition of this story: AppsFlyer Web SDK Temporarily Delivered Crypto‑stealing JavaScript