Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps

2026-05-20T01:24:08Z29857f8e66189eb160cdb0f714925ace50df542ff7e2b61a517db7bd0c804c5f
CVE-2026-20182CVE-2026-31635CVE-2026-42897CVE-2026-42945CVE-2026-8043MFA-bypassOAuth-consent-phishingandroid-ad-fraudcredential-theftgithub-actionsincident-responsemalvertisingnpmprivilege-escalationremote-code-executionsupply-chainthreat-actor-operationsvscode-extensionwordpress-skimming

What happened

A surge of high-impact security incidents and supply-chain attacks was reported: a large Android ad-fraud/malvertising campaign (Trapdoor) leveraged 455 malicious apps to generate ~659 million daily bid requests; multiple supply-chain compromises hit npm, GitHub Actions, VS Code extensions and TanStack, stealing credentials and infecting developer devices; active exploitation and proof-of-concept releases were disclosed for several high-severity flaws (NGINX, Exchange, Linux DirtyDecrypt LPE, Windows MiniPlasma), and vendors (Ivanti, Cisco SD‑WAN, SEPPMail, others) issued urgent patches. OAuth

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
29857f8e66189eb160cdb0f714925ace50df542ff7e2b61a517db7bd0c804c5f
Enrichment time
2026-05-20T01:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.