More than one in eight apps marketed to U.S. military personnel contain code from companies based in China, Russia, or other nations the Pentagon classifies as adversaries. That’s not a think-tank white paper. It comes from a multi-university study by researchers at Purdue, West Point, and Florida International University, who analyzed more than 220 military-targeted apps pulled from Google Play and military subreddits. The Pentagon declined to comment on the findings.
How Foreign Code Sneaks In Without Anyone Noticing
Third-party software modules buried in ad tools and notification services create invisible pipelines to adversarial nations.
SDKs — prefabricated code modules handling ads, analytics, and push notifications — appeared in 64% of the analyzed apps. Twelve carried Huawei’s HMS Core, including apps built for state National Guard organizations. In at least one case, Huawei code arrived as a transitive dependency bundled inside a commercial notification tool, meaning SDK code can be updated remotely — dormant access today could become active data collection tomorrow. The developer had no explicit awareness it was there. No data was observed flowing to Huawei servers, but researchers emphasize that doesn’t make the presence benign. The risk of compromised password vaults and sensitive credentials underscores how quietly these vulnerabilities can persist.
Key findings from the study:
- 7% of apps carried code from Pentagon-designated adversarial nations
- 40% collected or shared more data than their app-store privacy labels disclosed
- Yandex-linked Russian ad services appeared in apps used by military-affiliated users
- Pushwoosh, a Russian SDK company that posed as U.S.-based, previously embedded code in official U.S. Army and CDC apps before Reuters exposed the connection in 2022; both organizations removed it after the disclosure
- The Pentagon declined to comment on the study’s findings
“We hope the research helps military-affiliated personnel, developers, and platforms make more informed privacy decisions,” said lead author Joshua Shinkle of Purdue University. “We are grateful for the opportunity to bring greater attention to these issues and encourage continued discussion with developers, platforms, and policymakers about how to address these gaps.”
The Real-World Stakes Are No Longer Theoretical
Commercial location data has already been weaponized against deployed U.S. forces in active theaters.
The ad-tech ecosystem treats a deployed soldier the same as someone browsing for sneakers. Routine location data can reveal troop movements, base routines, and deployment patterns. In April, CENTCOM acknowledged in a letter to Senator Ron Wyden that it had received multiple threat reports of adversaries exploiting commercial location data to target U.S. personnel near Iran and the Strait of Hormuz. Lawmakers described it as the first official confirmation that troops in an active war zone were being tracked through the commercial data-broker system. A comparable surveillance app case demonstrated how readily such tools can be turned against specific populations.
Survey data from 103 military-affiliated Americans in the study exposed a sharp paradox. Over 83% reported using at least one app with data practices that made them uncomfortable. Between 76% and 83% said they were extremely uncomfortable with apps containing code from adversarial nations. Yet respondents actually felt more comfortable sharing data when an app carried military branding — like trusting a restaurant purely because the sign says “Mom’s Kitchen.” Nearly two-thirds had received little or no institutional guidance on personal app security.
What Troops Actually Want Done About It
In-phone warnings flagging foreign third-party code ranked as both the most effective and most widely supported fix among surveyed military personnel.
Respondents backed in-phone alerts as their top solution, alongside:
- federal restrictions on data-broker trading of military-affiliated data
- independent app audits
- stricter bans on foreign SDKs in military-marketed apps
All drew strong support. The Marine Corps already bans gambling, dating, and cryptocurrency apps from government-issued phones and warns against TikTok and WeChat. That covers the issued device. The problem is the personal phone in a service member’s pocket, carrying apps no policy is currently watching.
The fix isn’t complicated in concept: app stores need country-of-origin labeling for embedded SDKs, and developers need to audit their own dependency chains. Europe’s moves to restrict how companies handle government health, financial, and legal data offer one model for how policy can enforce data-sovereignty standards. Until that happens, the military logo on an app icon tells you nothing about what’s running underneath it.





























