Hackers hijack AppsFlyer Web SDK to steal cryptocurrency
Mar 14, 2026 // 18:11 - Norina Velotta


On March 10, 2026, AppsFlyer reported a supply chain compromise affecting its Web SDK. Between 01:00 and 10:00 UTC, websites loading the SDK from the official CDN served a malicious JavaScript payload designed to steal cryptocurrency and sensitive user data.

The Incident Details

  • The Hijack: The attack involved a DNS/CDN hijack. Records for websdk.appsflyer.com were redirected from AWS to a different provider (GCore), allowing attackers to distribute a modified version of the SDK.
  • Malicious Payload: The script was a modular, professional-grade interception framework containing seven distinct modules.
    • Theft Targets: It focused on swapping cryptocurrency wallet addresses (clipping) and intercepting payment data.
    • Advanced Features: The code used polymorphic obfuscation to dodge security scanners and “value-threshold targeting” to focus on high-value victims.
  • Command & Control: A suspicious endpoint, ://websdk.appsflyer.com, was used to manage the malicious modules.

Immediate Recommendations

If your site utilized the AppsFlyer Web SDK during the breach window:

  1. Audit Logs: Check traffic logs for the window between 01:00 and 10:00 UTC on March 10.
  2. Purge Caches: Force a refresh of the SDK on your site and clear CDN caches to ensure the clean, restored version is served to users.
  3. User Alerting: Advise users who interacted with crypto or payment forms during that window to monitor their accounts for unauthorized activity.

This event highlights a growing trend in 2026 of targeting trusted third-party providers to compromise thousands of downstream websites simultaneously.

#hackers  #hijack appsflyer  #news  #sdk to  #steal cryptocurrency  #web   —   News