cross-posted from: https://lemmy.today/post/42851505

Slightly more detail in this GitHub issue, however much is still unknown, even after three or so days. The dev hasn’t revealed any further details. Some articles on this incident:

Note that the articles provide little detail on what’s happened, mostly just detail that a malicious library was found and Play Protect started removing the app if affected. It’s unclear which versions are specifically affected, how the dev got breached, and what the malware actually does. According to a user (who may or may not be using some sort of LLM, their comment sounds like one at least) in a separate, related issue, the malware may collect device info and send to a command & control server. It could (in theory) receive new instructions at any point if it’s a C2 server. Again, it does appear that they had an LLM of some sort generate their comment, so take it with a grain of salt.

I’m going to uninstall the app and revoke access on my Google account page. I see little reason to need to reset my password as of right now, since the app uses an API key and not my actual password. In my opinion, it’s possibly related to YT viewbotting and commenting, or to add your device to a botnet. It’s unclear to me how this botnet would work in practice, since even Android TV sandboxes apps (for the most part).

  • qwestjest78@lemmy.ca
    link
    fedilink
    English
    arrow-up
    0
    ·
    14 days ago

    I loved SmartTube, but I moved away from my Android TV when Google started saying they are not going to allow side loading apps. Google has walked back that policy a bit, but I am much happier now with my alternatives and the knowledge that Google can’t wreck them with their future bull shit.

    That said SmartTube is a goat and it is sad to hear that such a great app has been compromised like this.