Malware, termed “Xamalicious”, was found in over a dozen Google Play Store apps by McAfee researchers, potentially stealing sensitive data and running ad fraud. These apps were downloaded more than 330,000 times globally, predominantly in the US, UK, and Germany. Once enabled, the malware could access a range of personal and device information. Despite Google removing the malicious apps, users who downloaded them previously remain vulnerable.

The NCSC wants developers to get serious on software security
The NCSC’s new Software Security Code of Practice has been praised by cyber professionals as a significant advancement in enhancing software supply chain security.