Study Finds Chinese and Russian Code Embedded in Apps Marketed to U.S. Military Personnel
STATUS: Supply-Chain Vulnerability SEVERITY: 6/10 AUDIENCE: Government, Defense, Critical Infrastructure Security Leads
Jul 30, 2026
·Blog
·Secure Communications
%3Aquality(100)&w=3840&q=75)
A multi-university analysis of more than 220 Android apps built for service members finds foreign-sourced software components in the majority of them, including code tied to companies in nations the Pentagon classifies as strategic adversaries.
What Happened — and Why It Is Different
A supply-chain risk hiding in plain sight, not a breach. Researchers from Purdue University, the U.S. Military Academy at West Point, and Florida International University analyzed more than 220 Android apps marketed directly to U.S. military personnel and their families 1— fitness trackers, deployment and PT tools, benefits calculators, community forums, and apps affiliated with state National Guard organizations.1 Led by Purdue's Joshua Shinkle, the study found that 64 percent of these apps contain embedded third-party software development kits (SDKs) sourced from outside the United States, and more than one in eight apps carry code from companies based in nations the Pentagon classifies as strategic adversaries, including China and Russia.¹
Huawei's HMS Core, a mobile services framework built by the Chinese telecom manufacturer, was found embedded in at least 12 of the analyzed apps, including some affiliated with state National Guard organizations.² SDKs typically power routine functions — maps, analytics, cloud services, push notifications — and are used throughout the mobile app industry, meaning most developers didn't write risky code themselves; they built on commercial libraries and open-source components without auditing where the underlying pieces originated. Separately, the study found that 40 percent of the apps collected or shared more user data than their developers disclosed in Apple App Store or Google Play privacy labels.¹
The researchers found no evidence that the observed SDKs are currently being used to exfiltrate data or conduct surveillance, but caution that SDKs can receive updates over time, meaning code that looks benign today could change after a user has already installed and trusted the app.² This isn't a new pattern: Pushwoosh, a Russian SDK company that had marketed itself as U.S.-based, was previously found embedded in official U.S. Army and CDC apps before Reuters exposed the connection in 2022; both organizations removed it only after the disclosure.³ The Pentagon declined to comment on the new findings.¹
What The Study Found — And What It Means
Finding | What It Means | Operational Consequence | Open Question |
64 percent of analyzed apps contain foreign-sourced third-party SDKs.¹ | Routine functions like maps, analytics, and push notifications are commonly outsourced to third-party code the app's own developer didn't write. | A service member's fitness tracker or benefits app can carry a data pipeline to an external company without the app developer intending it. | How many of these SDKs have remote update mechanisms that could change their behavior after install. |
More than 1 in 8 apps carry code from adversary-nation companies, including 12 with Huawei's HMS Core.² | Nation-state-linked companies gain a foothold inside apps used by service members and, in some cases, official National Guard units. | Even absent current misuse, the pipeline for future data collection already exists inside trusted, military-marketed apps. | Whether any of these SDKs have received updates since installation that changed their data-handling behavior. |
40 percent of apps collect or share more data than their privacy labels disclose.¹ | Standard app-store privacy labels significantly understate what these apps actually do with user data. | Personnel and family members installing a labeled app are consenting to less than what is actually being collected. | What data has already been collected under this gap, and where it currently resides. |
A documented precedent (Pushwoosh in Army/CDC apps) shows disclosure is what triggered removal.³ | A Russian SDK company previously posed as U.S.-based inside official Army and CDC apps until Reuters exposed it in 2022. | Detection has historically depended on outside journalism, not internal vetting, before affected apps were remediated. | Whether this larger-scale, peer-reviewed finding prompts systematic vetting or another one-off removal cycle. |
Why This Matters
Old Assumption | Current Reality | BlackBerry Response |
App store privacy labels and basic publisher vetting are sufficient to know what a mobile app actually does with a user's data. | 40 percent of apps marketed to military personnel collect or share more data than their privacy labels disclose, and the underlying SDK supply chain is invisible to the label entirely.¹ | UEM application vetting and allowlisting policy evaluates what an app and its embedded components actually do on a managed device, not what a storefront label claims. |
Consumer and lifestyle apps installed on personal devices sit outside the scope of government device security programs. | Deployment tools, PT trackers, and benefits calculators built for service members carry the same foreign-code supply-chain risk as any consumer app, and several are tied to official state National Guard organizations.² | UEM policy extends beyond core productivity apps to flag and restrict foreign-sourced SDKs across the full range of apps personnel are likely to install, including those marketed specifically to them. |
A supply-chain risk that hasn't been actively exploited yet isn't a priority. | SDKs can be updated post-install, so code vetted as safe at install time can change behavior later without any user action.² The Pushwoosh precedent shows this exact pattern went undetected for years.3 | Continuous UEM compliance monitoring evaluates managed devices and their installed software on an ongoing basis, catching a downstream SDK update rather than only the initial install. |
Recommended Actions
IMMEDIATE | Inventory mobile apps in use by military personnel, National Guard-affiliated units, and government-adjacent staff for the specific pattern this study identifies — third-party SDKs from adversary-nation companies, particularly Huawei's HMS Core. |
IMMEDIATE | Cross-reference the Purdue/West Point/FIU findings against any apps distributed or recommended through official military or National Guard channels. |
SHORT-TERM | Extend UEM application vetting and allowlisting policy to evaluate embedded third-party SDKs, not just the top-level app developer or publisher. |
SHORT-TERM | Enroll personnel devices in continuous UEM compliance monitoring so a benign SDK that receives a later, riskier update is caught after installation, not only at initial vetting. |
ONGOING | Track whether this study prompts a Pentagon-level app vetting requirement, given the department has declined to comment so far. |
BlackBerry Position
A privacy label tells you what a developer says an app does. It says nothing about the third-party code quietly running inside it, and the study found that privacy labels frequently understated actual data collection and sharing behavior.¹ For any device carrying government or military-adjacent data, vetting has to reach the full supply chain, not just the storefront listing.
Citations:
Apps Marketed to US Troops Are Shipping Chinese and Russian Code
(WIRED, July 20, 2026).Military-Focused Apps Contain Foreign-Sourced Code, Raising Data Security Concerns
(SC Media, July 21, 2026).Apps Marketed to US Troops Are Shipping Chinese and Russian Code
(WIRED discussion of the Pushwoosh precedent and Reuters' 2022 reporting).
Study Finds Chinese and Russian Code Embedded in Apps Marketed to U.S. Military Personnel
STATUS: Supply-Chain Vulnerability SEVERITY: 6/10 AUDIENCE: Government, Defense, Critical Infrastructure Security Leads
Jul 30, 2026
·Blog
·Secure Communications
%3Aquality(100)&w=3840&q=75)
A multi-university analysis of more than 220 Android apps built for service members finds foreign-sourced software components in the majority of them, including code tied to companies in nations the Pentagon classifies as strategic adversaries.
What Happened — and Why It Is Different
A supply-chain risk hiding in plain sight, not a breach. Researchers from Purdue University, the U.S. Military Academy at West Point, and Florida International University analyzed more than 220 Android apps marketed directly to U.S. military personnel and their families 1— fitness trackers, deployment and PT tools, benefits calculators, community forums, and apps affiliated with state National Guard organizations.1 Led by Purdue's Joshua Shinkle, the study found that 64 percent of these apps contain embedded third-party software development kits (SDKs) sourced from outside the United States, and more than one in eight apps carry code from companies based in nations the Pentagon classifies as strategic adversaries, including China and Russia.¹
Huawei's HMS Core, a mobile services framework built by the Chinese telecom manufacturer, was found embedded in at least 12 of the analyzed apps, including some affiliated with state National Guard organizations.² SDKs typically power routine functions — maps, analytics, cloud services, push notifications — and are used throughout the mobile app industry, meaning most developers didn't write risky code themselves; they built on commercial libraries and open-source components without auditing where the underlying pieces originated. Separately, the study found that 40 percent of the apps collected or shared more user data than their developers disclosed in Apple App Store or Google Play privacy labels.¹
The researchers found no evidence that the observed SDKs are currently being used to exfiltrate data or conduct surveillance, but caution that SDKs can receive updates over time, meaning code that looks benign today could change after a user has already installed and trusted the app.² This isn't a new pattern: Pushwoosh, a Russian SDK company that had marketed itself as U.S.-based, was previously found embedded in official U.S. Army and CDC apps before Reuters exposed the connection in 2022; both organizations removed it only after the disclosure.³ The Pentagon declined to comment on the new findings.¹
What The Study Found — And What It Means
Finding | What It Means | Operational Consequence | Open Question |
64 percent of analyzed apps contain foreign-sourced third-party SDKs.¹ | Routine functions like maps, analytics, and push notifications are commonly outsourced to third-party code the app's own developer didn't write. | A service member's fitness tracker or benefits app can carry a data pipeline to an external company without the app developer intending it. | How many of these SDKs have remote update mechanisms that could change their behavior after install. |
More than 1 in 8 apps carry code from adversary-nation companies, including 12 with Huawei's HMS Core.² | Nation-state-linked companies gain a foothold inside apps used by service members and, in some cases, official National Guard units. | Even absent current misuse, the pipeline for future data collection already exists inside trusted, military-marketed apps. | Whether any of these SDKs have received updates since installation that changed their data-handling behavior. |
40 percent of apps collect or share more data than their privacy labels disclose.¹ | Standard app-store privacy labels significantly understate what these apps actually do with user data. | Personnel and family members installing a labeled app are consenting to less than what is actually being collected. | What data has already been collected under this gap, and where it currently resides. |
A documented precedent (Pushwoosh in Army/CDC apps) shows disclosure is what triggered removal.³ | A Russian SDK company previously posed as U.S.-based inside official Army and CDC apps until Reuters exposed it in 2022. | Detection has historically depended on outside journalism, not internal vetting, before affected apps were remediated. | Whether this larger-scale, peer-reviewed finding prompts systematic vetting or another one-off removal cycle. |
Why This Matters
Old Assumption | Current Reality | BlackBerry Response |
App store privacy labels and basic publisher vetting are sufficient to know what a mobile app actually does with a user's data. | 40 percent of apps marketed to military personnel collect or share more data than their privacy labels disclose, and the underlying SDK supply chain is invisible to the label entirely.¹ | UEM application vetting and allowlisting policy evaluates what an app and its embedded components actually do on a managed device, not what a storefront label claims. |
Consumer and lifestyle apps installed on personal devices sit outside the scope of government device security programs. | Deployment tools, PT trackers, and benefits calculators built for service members carry the same foreign-code supply-chain risk as any consumer app, and several are tied to official state National Guard organizations.² | UEM policy extends beyond core productivity apps to flag and restrict foreign-sourced SDKs across the full range of apps personnel are likely to install, including those marketed specifically to them. |
A supply-chain risk that hasn't been actively exploited yet isn't a priority. | SDKs can be updated post-install, so code vetted as safe at install time can change behavior later without any user action.² The Pushwoosh precedent shows this exact pattern went undetected for years.3 | Continuous UEM compliance monitoring evaluates managed devices and their installed software on an ongoing basis, catching a downstream SDK update rather than only the initial install. |
Recommended Actions
IMMEDIATE | Inventory mobile apps in use by military personnel, National Guard-affiliated units, and government-adjacent staff for the specific pattern this study identifies — third-party SDKs from adversary-nation companies, particularly Huawei's HMS Core. |
IMMEDIATE | Cross-reference the Purdue/West Point/FIU findings against any apps distributed or recommended through official military or National Guard channels. |
SHORT-TERM | Extend UEM application vetting and allowlisting policy to evaluate embedded third-party SDKs, not just the top-level app developer or publisher. |
SHORT-TERM | Enroll personnel devices in continuous UEM compliance monitoring so a benign SDK that receives a later, riskier update is caught after installation, not only at initial vetting. |
ONGOING | Track whether this study prompts a Pentagon-level app vetting requirement, given the department has declined to comment so far. |
BlackBerry Position
A privacy label tells you what a developer says an app does. It says nothing about the third-party code quietly running inside it, and the study found that privacy labels frequently understated actual data collection and sharing behavior.¹ For any device carrying government or military-adjacent data, vetting has to reach the full supply chain, not just the storefront listing.
Citations:
Apps Marketed to US Troops Are Shipping Chinese and Russian Code
(WIRED, July 20, 2026).Military-Focused Apps Contain Foreign-Sourced Code, Raising Data Security Concerns
(SC Media, July 21, 2026).Apps Marketed to US Troops Are Shipping Chinese and Russian Code
(WIRED discussion of the Pushwoosh precedent and Reuters' 2022 reporting).
%3Aquality(100)&w=3840&q=75)