# AppsFlyer Web SDK Supply Chain Hijack via Domain Registrar Compromise for Cryptocurrency Theft

> The AppsFlyer Web SDK (websdk.appsflyer.com) was hijacked through a domain registrar compromise on March 9-10, 2026. A professional-grade 7-module JavaScript interception framework replaced cryptocurrency wallet addresses (Bitcoin, Ethereum, Solana, Ripple, TRON) with attacker-controlled wallets while maintaining normal SDK functionality. With 15,000 businesses and 100,000+ apps relying on the SDK, the supply chain blast radius was massive.

- **Published:** 2026-03-14T12:00:00Z
- **Last reviewed:** 2026-03-14T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0229
- **ID:** TL-2026-0229
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** RESOLVED
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On March 9, 2026, security firm Profero discovered that the AppsFlyer Web SDK, served from websdk.appsflyer.com, was delivering a malicious JavaScript payload to all websites loading the SDK. AppsFlyer confirmed a domain registrar incident that gave attackers control over the appsflyer.com domain, enabling them to serve malicious code from the legitimate SDK endpoint.

The malicious payload was a ~170 KB minified JavaScript file — far larger and more sophisticated than a typical crypto clipper. Analysis revealed a professional-grade interception framework with seven distinct modules: ActuateElements (DOM mutation surveillance), ConsoleGuard (console output suppression for anti-forensics), Destinations (attacker wallet management), KillElements (anti-forensics element removal), NetHooksmith (network request/response interception), XorCipherBytes (XOR encryption for C2 communications), and Accounting/AccountingForTransfer (portfolio tracking and transfer monitoring).

The payload employed multi-layered obfuscation using base91 string encoding with 17 distinct shuffled alphabets. Dead code injection — including LRU caches, linked-list helpers, anagram checkers, and SHA-256 implementations — further obscured analysis. Runtime-only string resolution defeated static analysis tools. Function names (oFmFNH, iVp0dU7, byZJpo, fLOUxWf) and class names (wPwwVol, QA903T, IE62Yb) were randomized.

The operational attack chain worked as follows: (1) The payload replaced globalThis.fetch with a proxy function (wlpPd2t) and patched XMLHttpRequest.prototype.open/send/setRequestHeader via SLkiCz() to intercept all network traffic. (2) Five regex-based interceptors — one per cryptocurrency format (Bitcoin, Ethereum, Solana, Ripple, TRON) — scanned fetch/XHR response bodies for wallet addresses. (3) MutationObserver-based DOM watchers (classes wPwwVol, QA903T) monitored input fields in real-time and swapped wallet values on change events. (4) Matched addresses were replaced with attacker-controlled wallets fetched at runtime from the C2 server via function p58Xob(). (5) Original addresses, page URLs, and timestamps were exfiltrated via XOR-encrypted POST requests to the C2 server.

A suspicious endpoint websdk.appsflyer.com/v1/api/plugin was observed during the compromise window and is not present in AppsFlyer's normal documentation — this was likely the C2 endpoint used for wallet address distribution and data exfiltration. Because the C2 provided runtime configuration, the framework was capable of arbitrary data interception per C2 instruction — the crypto-clipping behavior was just the observed mode of operation.

AppsFlyer's official exposure window was March 9, 20:40 UTC to March 10, 10:30 UTC (approximately 14 hours). Profero researchers estimated a broader window from March 9, 22:45 UTC through March 11. AppsFlyer confirmed the mobile SDK was not affected and stated their investigation found no evidence of customer data on AppsFlyer systems being accessed. The company resolved the domain registrar issue and notified customers directly. The domain was fully restored by March 12, 2026.

Given that AppsFlyer's SDK platform serves 15,000 businesses across 100,000+ mobile and web applications — spanning e-commerce, fintech, healthcare, and SaaS sectors — the blast radius of this supply chain compromise was exceptionally large. Any website loading the SDK during the exposure window served the malicious payload to its visitors. The attack demonstrates how third-party marketing analytics SDKs, widely trusted and deeply embedded in web applications, represent high-value supply chain targets.

## MITRE ATT&CK

- T1584 Compromise Infrastructure
- T1195 Supply Chain Compromise
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1070 Indicator Removal
- T1185 Browser Session Hijacking
- T1115 Clipboard Data
- T1056 Input Capture
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1041 Exfiltration Over C2 Channel
- T1565 Data Manipulation

## Sources

- [AppsFlyer Web SDK hijacked to spread crypto-stealing JavaScript code](https://www.bleepingcomputer.com/news/security/appsflyer-web-sdk-used-to-spread-crypto-stealer-javascript-code/)
- [AppsFlyer JavaScript SDK Has Been Compromised — Feroot Security](https://www.feroot.com/blog/appsflyers-javascript-sdk-has-been-compromised/)
- [AppsFlyer Web SDK Compromise: Independent Payload Analysis — Daniel Smith](https://medium.com/@_ifnull/appsflyer-web-sdk-compromise-independent-payload-analysis-109afd72aba9)
- [AppsFlyer SDK compromised 2026-03-10 — GitHub Gist Analysis (cometkim)](https://gist.github.com/cometkim/5bea18688e1653d2c3fe5476d3efed12)
- [Compromised AppsFlyer SDK malicious payload — Pastebin](https://pastebin.com/b9tg64Ub)
- [AppsFlyer appsflyer.com domain availability incident — Status Page](https://status.appsflyer.com/history)
- [AppsFlyer domain availability incident timeline — IsDown](https://isdown.app/status/appsflyer/incidents/551696-appsflyer-com-domain-availability)
- [Hacker News discussion — Appsflyer SDK Hijacked](https://news.ycombinator.com/item?id=47319115)
- [MalwareTips Forum — AppsFlyer Web SDK hijacked](https://malwaretips.com/threads/appsflyer-web-sdk-hijacked-to-spread-crypto-stealing-javascript-code.140245/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0229
