AppsFlyer Web SDK hijacked to spread crypto-stealing JavaScript code
2026-03-14T19:23:25Z•125e62a57e7d107b9972fad00c7ed56185a06c396c597ed2c61da14423c692ee
AI-generated malwareAppsflyerRCESamsungSocksEscortSteamStorm-2561VeeamWindows 11chromecredential theftcrypto‑stealerdata breachfake VPNjavascriptlaw enforcementmalware distributionpatchproxy networkransomwaresinkholesupply-chainupdate regressionweb-sdkzero-day
What happened
Multiple high-impact security events reported: a supply‑chain compromise of the AppsFlyer Web SDK briefly injected JavaScript crypto‑stealer code; Google and Veeam released emergency patches for exploited Chrome zero‑days and multiple critical RCE flaws in Veeam Backup & Replication; Microsoft is investigating a Windows 11 issue on some Samsung PCs after February 2026 updates that can block access to the C: drive; the FBI seeks victims after malicious Steam games distributed malware; law enforcement sinkholed ~45,000 IPs in an international takedown and disrupted the SocksEscort proxy network;
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 125e62a57e7d107b9972fad00c7ed56185a06c396c597ed2c61da14423c692ee
- Enrichment time
- 2026-03-14T19:23:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.