Ссылка
click to show
click to show
SmartTube infected with botnet malware
Summary
The popular YouTube Android app alternative "SmartTube" for Android TVs and Android Streaming devices (like NVidia shield, Google TV Streamer, Amazon FireTV, etc.) has been confirmed to be infected with botnet malware. Users are advised to at the very least revoke any access given to SmartTube via their Google Account settings, remove the app if still installed and make sure to re-install only a version that has been confirmed to be clean. Reportedly all release channels (website, in-app updates, GitHub) were affected.
Quotes
Quote
Non-technical summary:
The app shipped with a hidden native library called libalphasdk.so.
When SmartTube starts, it launches this library and sends a registration message to its own servers.
Before sending, it collects and transmits: device model and manufacturer, Android version, your network operator name, whether you are on Wi‑Fi or mobile data, your app package name, the app’s internal files path, a unique ID it stores, your local IP it previously saved, and a flag if Firebase is present.
It keeps a background timer that repeatedly “checks registration” with the server every second.
Another timer runs every minute to measure how much bandwidth the app uses; it stores usage locally and enforces a server-provided bandwidth limit.
The native code contains its own DNS/HTTPS client and hardcoded Google endpoints (drive.google.com, dns.google, www.google.com) suggesting it downloads commands or config from Google infrastructure to hide.
No user prompts or controls: all of this happens silently when the app runs.
What this means for you: your device details and network info were likely uploaded; the app could also pull further instructions from the internet. If you used real accounts on that device, treat it as untrusted, change passwords from a clean device, and uninstall/replace with a known-clean build.
Quote
Important announcement about the app
My development environment was infected by unknown malicious software, as a result of which a few builds may have been affected. Once the issue was detected, I secured everything with a full disk wipe, restored a clean setup, and now all builds are scanned with VirusTotal. The F-Droid version will also be verified before release.
Public keys may have been compromised, which is why I am sharing this issue. You can download the new version and the new public key below, and instructions for restoring backups are provided.
No extra actions are required since the app uses one-time connection codes. These codes have very limited permissions (for example, they cannot change your password). Still, you can revo