MavenGate Supply Chain Attack Let Attackers Hijack Java & Android Apps
https://gbhackers.com/mavengate-hijack-apps/
Given the recent supply chain attacks in the “web world”, we have conducted a study on the possibility of supply chain attacks in the mobile application world.
In the course of our research, we found utter chaos that extends far beyond the Android world. Many public and popular libraries that have long been abandoned are still being used in huge projects. Access to projects can be hijacked through domain name purchases and since most default build configurations are vulnerable, it would be difficult or even impossible to know whether an attack was being performed
https://blog.oversecured.com/Introducing-MavenGate-a-supply-chain-attack-method-for-Java-and-Android-applications