Malware, IoT, Application security, Supply chain

Malware injected into SmartTube app for Android TV

Privacy concept: pixelated words Malware on digital background, 3d render

Malware has been spread in a recent update of the widely used open-source SmartTube YouTube client for Android TV after its developer's signing keys were compromised last week, reports BleepingComputer.

Included in the impacted SmartTube version number 30.51 was a concealed native library that covertly operated in the background while conducting host device fingerprinting and registration, as well as periodic metric delivery and configuration retrieval through an encrypted communications channel, according to a user who reverse-engineered the app.

Such a library may potentially be malware, said SmartTube developer Yuriy Yuliskov, who already voided the old signature while announcing the imminent release of a new version that has a separate app ID.

With additional details regarding the compromise still uncertain, affected users have been urged to remain on older SmartTube builds, refrain from premium account access, and deactivate auto-updates, as well as monitor unauthorized access, omit suspicious services, and conduct Google Account credential resets.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds