Threat reportSupply ChainTL-2026-0229

AppsFlyer Web SDK Supply Chain Hijack via Domain Registrar Compromise for Cryptocurrency Theft

highRESOLVED

AppsFlyer Web SDK Supply Chain Hijack via Domain Registrar (TL-2026-0229), also tracked as AppsFlyer SDK Hijack, is a high-severity supply-chain compromise, first published 2026-03-14. It has no confirmed attribution, affects AppsFlyer Web SDK, maps to 14 MITRE ATT&CK techniques (T1027, T1041, T1056), and is covered by 9 detection rules and 15 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
14MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-0229

Threat ID
TL-2026-0229
Also known as
AppsFlyer SDK Hijack, AppsFlyer Crypto Clipper
Severity
HIGH
Status
RESOLVED
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
technology, e-commerce, financial, healthcare, saas, marketing, advertising, mobile-applications
Target regions
Global
Detection rules
9
Indicators of compromise
15

Malware and tooling in AppsFlyer Web SDK Supply Chain Hijack via Domain Registrar

Malware and tooling: AppsFlyer SDK Crypto Clipper

How AppsFlyer Web SDK Supply Chain Hijack via Domain Registrar works

The AppsFlyer Web SDK (websdk.appsflyer.com) was hijacked through a domain registrar compromise on March 9-10, 2026. A professional-grade 7-module JavaScript interception framework replaced cryptocurrency wallet addresses (Bitcoin, Ethereum, Solana, Ripple, TRON) with attacker-controlled wallets while maintaining normal SDK functionality. With 15,000 businesses and 100,000+ apps relying on the SDK, the supply chain blast radius was massive.

On March 9, 2026, security firm Profero discovered that the AppsFlyer Web SDK, served from websdk.appsflyer.com, was delivering a malicious JavaScript payload to all websites loading the SDK. AppsFlyer confirmed a domain registrar incident that gave attackers control over the appsflyer.com domain, enabling them to serve malicious code from the legitimate SDK endpoint.

The malicious payload was a ~170 KB minified JavaScript file — far larger and more sophisticated than a typical crypto clipper. Analysis revealed a professional-grade interception framework with seven distinct modules: ActuateElements (DOM mutation surveillance), ConsoleGuard (console output suppression for anti-forensics), Destinations (attacker wallet management), KillElements (anti-forensics element removal), NetHooksmith (network request/response interception), XorCipherBytes (XOR encryption for C2 communications), and Accounting/AccountingForTransfer (portfolio tracking and transfer monitoring).

The payload employed multi-layered obfuscation using base91 string encoding with 17 distinct shuffled alphabets. Dead code injection — including LRU caches, linked-list helpers, anagram checkers, and SHA-256 implementations — further obscured analysis. Runtime-only string resolution defeated static analysis tools. Function names (oFmFNH, iVp0dU7, byZJpo, fLOUxWf) and class names (wPwwVol, QA903T, IE62Yb) were randomized.

The operational attack chain worked as follows: (1) The payload replaced globalThis.fetch with a proxy function (wlpPd2t) and patched XMLHttpRequest.prototype.open/send/setRequestHeader via SLkiCz() to intercept all network traffic. (2) Five regex-based interceptors — one per cryptocurrency format (Bitcoin, Ethereum, Solana, Ripple, TRON) — scanned fetch/XHR response bodies for wallet addresses. (3) MutationObserver-based DOM watchers (classes wPwwVol, QA903T) monitored input fields in real-time and swapped wallet values on change events. (4) Matched addresses were replaced with attacker-controlled wallets fetched at runtime from the C2 server via function p58Xob(). (5) Original addresses, page URLs, and timestamps were exfiltrated via XOR-encrypted POST requests to the C2 server.

A suspicious endpoint websdk.appsflyer.com/v1/api/plugin was observed during the compromise window and is not present in AppsFlyer's normal documentation — this was likely the C2 endpoint used for wallet address distribution and data exfiltration. Because the C2 provided runtime configuration, the framework was capable of arbitrary data interception per C2 instruction — the crypto-clipping behavior was just the observed mode of operation.

AppsFlyer's official exposure window was March 9, 20:40 UTC to March 10, 10:30 UTC (approximately 14 hours). Profero researchers estimated a broader window from March 9, 22:45 UTC through March 11. AppsFlyer confirmed the mobile SDK was not affected and stated their investigation found no evidence of customer data on AppsFlyer systems being accessed. The company resolved the domain registrar issue and notified customers directly. The domain was fully restored by March 12, 2026.

Given that AppsFlyer's SDK platform serves 15,000 businesses across 100,000+ mobile and web applications — spanning e-commerce, fintech, healthcare, and SaaS sectors — the blast radius of this supply chain compromise was exceptionally large. Any website loading the SDK during the exposure window served the malicious payload to its visitors. The attack demonstrates how third-party marketing analytics SDKs, widely trusted and deeply embedded in web applications, represent high-value supply chain targets.

MITRE ATT&CK techniques used in TL-2026-0229

defense-evasion

T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information

exfiltration

T1041 Exfiltration Over C2 Channel

collection

T1056 Input Capture; T1115 Clipboard Data; T1185 Browser Session Hijacking

execution

T1059 Command and Scripting Interpreter; T1204 User Execution

command-and-control

T1071 Application Layer Protocol; T1573 Encrypted Channel

initial-access

T1195 Supply Chain Compromise

impact

T1565 Data Manipulation

resource-development

T1584 Compromise Infrastructure

Affected products and versions in AppsFlyer Web SDK Supply Chain Hijack via Domain Registrar

  • AppsFlyer — Web SDK
    Vulnerable versions: All versions served from websdk.appsflyer.com during March 9-11, 2026
    Fixed in: Versions served after domain restoration on March 12, 2026
  • AppsFlyer — Mobile SDK
    Fixed in: Not affected

Remediation for AppsFlyer Web SDK Supply Chain Hijack via Domain Registrar

Patches

  • Update to the latest clean version of the AppsFlyer Web SDK after verifying integrity
  • AppsFlyer has resolved the domain registrar issue — no specific patch required

Immediate actions

  • Audit all web pages that loaded the AppsFlyer SDK between March 9-11, 2026 for signs of compromise
  • Review telemetry logs for suspicious API requests to websdk.appsflyer.com/v1/api/plugin
  • Check for unexpected MutationObserver registrations and fetch/XHR proxy hooks in browser developer tools
  • Notify users who conducted cryptocurrency transactions during the exposure window to verify wallet addresses
  • Block the suspected C2 endpoint websdk.appsflyer.com/v1/api/plugin at the network perimeter

Workarounds

  • Self-host the AppsFlyer SDK from a known-good version rather than loading from CDN
  • Temporarily remove the AppsFlyer Web SDK until integrity can be verified
  • Implement CSP script-src directives that include hash-based allowlisting for SDK resources

Longer-term hardening

  • Implement Subresource Integrity (SRI) hashes for all third-party JavaScript resources
  • Deploy Content Security Policy (CSP) headers restricting script sources and connect-src directives
  • Use client-side JavaScript monitoring tools (e.g., Feroot, PerimeterX) to detect runtime code manipulation
  • Establish domain registrar security controls including registry locks, multi-factor authentication, and DNSSEC
  • Implement PCI DSS 4.0.1 Requirements 6.4.3 and 11.6.1 for payment page script integrity monitoring
  • Conduct regular third-party SDK security audits and maintain a software bill of materials (SBOM)

Weaknesses (CWE) in AppsFlyer Web SDK Supply Chain Hijack via Domain Registrar

CWE-829, CWE-506, CWE-494, CWE-350

Timeline of AppsFlyer Web SDK Supply Chain Hijack via Domain Registrar

  • Profero security researchers discover the malicious payload being served from the AppsFlyer Web SDK official domain
  • Malicious JavaScript payload first served from websdk.appsflyer.com at approximately 20:40 UTC following domain registrar compromise
  • Feroot Security publishes advisory identifying supply chain attack scope affecting e-commerce, fintech, healthcare, and SaaS platforms
  • AppsFlyer notifies customers directly about the compromise and provides incident updates via status page
  • AppsFlyer contains the domain registrar incident and resolves domain mapping issue at approximately 10:30 UTC, ending the primary exposure window
  • Independent researchers (cometkim GitHub Gist, community forums) begin analyzing the malicious payload, identifying 7-module interception framework
  • AppsFlyer identifies the domain availability issue at 04:09 UTC and begins investigation into potential vendor-related compromise
  • Daniel Smith (@_ifnull) publishes independent payload analysis on Medium detailing 7 modules, base91 obfuscation, and C2 architecture
  • AppsFlyer officially declares the domain availability incident resolved after DNS propagation completes
  • BleepingComputer publishes detailed coverage of the incident, bringing wider industry attention to the supply chain compromise
  • As of 2026-05-29, this AppsFlyer Web SDK crypto-clipper supply chain hijack is resolved: AppsFlyer regained domain control and fully restored websdk.appsflyer.com by March 12, 2026, ending the ~14-hour exposure window. No CVE/patch applies (domain registrar/DNS hijack), no recurrence or ongoing exploitation reported through May 2026, and the actor remains unattributed with no active campaign.

Sources cited for AppsFlyer Web SDK Supply Chain Hijack via Domain Registrar

Detection coverage for TL-2026-0229

As of 2026-03-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0229 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats