Attackers compromised the developer signing keys for the popular open-source SmartTube YouTube client for Android TV, enabling them to distribute a malicious update (version 30.51) to users. The injected malware, concealed as a native library (libalphasdk.so), was not part of the official source code and operated covertly in the background, performing device fingerprinting, registration with a remote backend, and periodic encrypted communications for metrics and configuration retrieval. The breach was detected after users reported Play Protect warnings, prompting the developer, Yuriy Yuliskov, to revoke the compromised keys and announce a new version with a separate app ID.
Users have been advised to avoid updating to the compromised version, disable auto-updates, refrain from using premium accounts, and monitor for unauthorized access or suspicious services. The developer has released safe beta and stable test builds, but the full extent of the compromise remains under investigation. Security experts recommend Google Account credential resets and heightened vigilance for those affected by the malicious update.

Trace attribution and downstream blast radius.
2 events from the most recent confirmed update back to the earliest known activity.
AhnLab ASEC released a public security incident report on the SmartTube compromise and advised users to remain alert for malicious activity related to the app. The report marked a technical and public disclosure of the incident by a security vendor.
The SmartTube app for Android TV was reportedly breached, allowing attackers to inject malware into an app update distributed to users. Multiple sources describe the incident as a supply-chain style compromise affecting the ad-free YouTube client.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceasec.ahnlab.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.