In late November 2025, attackers compromised SmartTube's signing keys, distributing malware via a malicious update to the popular open-source YouTube client for Android TV, affecting thousands. Google and Amazon remotely uninstalled affected versions. The breach highlights vulnerabilities in open-source apps, prompting calls for enhanced security practices and user vigilance.