News
AI SHIFT:

Smart TV Proxy SDKs Turn Free Apps Into a Hidden AI Scraping Supply Chain

Newsroom brief

Bright Data's SDK has been reverse-engineered in research showing how free apps can turn consumer devices, including smart TVs, into residential proxy nodes for web-scraping traffic. The issue matters because AI data harvesting is increasing demand for residential IPs, while consent screens and background network behavior may not be clear to users or IT teams.

Verified against source materialEdited by SendTech Times Cybersecurity Desk
Smart TV Proxy SDKs Turn Free Apps Into a Hidden AI Scraping Supply Chain
Image source: The Hacker News

Free apps become residential proxy infrastructure

Bright Data's consumer-app SDK has been reverse-engineered in research showing how free apps can turn user devices, including always-on smart TVs, into exit nodes for web-scraping traffic.

The company, previously known as Luminati, advertises more than 400 million residential IPs and describes an SDK-sourced pool of more than 150 million IPs.

The practical exposure is that a household connection and bandwidth can be used as someone else's scraping infrastructure.

Smart TVs are sensitive in that model because they are usually plugged in, connected to fast networks and left running for long periods.

Consent screens face a technical gap

The researcher found that the channel carrying scraping jobs lacked normal authentication controls and, on iOS, could bypass a configured VPN.

The SDK could also continue relaying traffic in the background while a user watched the screen or took a call, unless the battery was low.

One Roku app, Petflix, presented an opt-in screen saying the device and connection would be used occasionally.

The SDK settings reviewed in the research allowed up to 200 GB of traffic a month, with far higher limits in a few countries, including Uzbekistan and Oman.

AI demand changes the economics

Demand for residential IP addresses is rising as AI data harvesting runs into anti-bot defenses.

Cloudflare and DataDome can block scrapers using datacenter IPs and push scraping traffic toward residential connections.

That does not make consent-based proxy networks the same as criminal botnets.

Bright Data says its exit nodes opt in through a consent screen, while botnets hijack devices.

The question is whether that consent is specific and durable enough when the device may be a living-room TV.

What device owners and IT teams can watch

Bright Data's public partner list includes smart-TV app makers such as PlayWorks Digital, CloudTV and Longvision, although the list alone does not prove a current app still carries the SDK.

Google, Amazon and Roku have restricted background proxy SDKs, and Bright Data dropped those platforms while still listing Samsung's Tizen and LG's webOS.

For households, the actionable watchpoint is unusual background traffic from free apps to Bright Data SDK-related infrastructure.

Router-level tools such as Pi-hole or NextDNS can help reduce that exposure when the relevant domains are identified.

The practical question is whether app stores, device makers and network administrators can make background proxy use visible before residential bandwidth becomes a hidden AI supply chain.

Share this article
inXf

Related articles

More
Unit 42 Finds 13,229 Malicious URLs In AI Phantom-Domain Study
Cybersecurity

Unit 42 Finds 13,229 Malicious URLs In AI Phantom-Domain Study

Palo Alto Networks’ Unit 42 said its phantom-squatting research generated 685,339 prompts across 913 brands and produced 2.1 million unique URLs, including 13,229 malicious URLs and about 250,000 unique phantom domains. The public report did not disclose the brand list, affected customer names or named domains tied to data loss.

UAE Cyber Summit Puts AI Risk Inside A National Resilience Plan
Cybersecurity

UAE Cyber Summit Puts AI Risk Inside A National Resilience Plan

The UAE’s 3rd Government Cybersecurity Summit in Abu Dhabi framed cyber defence as a national resilience issue, linking AI-enabled threats, telecom exposure, data compression and regional cooperation.

Palo Alto Sell-Off Shows AI Cybersecurity Demand Still Has a Timing Problem
Cybersecurity

Palo Alto Sell-Off Shows AI Cybersecurity Demand Still Has a Timing Problem

Palo Alto Networks shares fell more than 4% after stronger quarterly results and current-quarter guidance failed to satisfy investors looking for faster AI-linked earnings upside. CEO Nikesh Arora reiterated a fiscal 2030 target of more than 4,000 platformizations and a USD 20 billion NGS ARR goal. The practical question is whether AI-related security demand turns into NGS ARR progress as data center infrastructure is ordered, installed and brought online.

WeedHack Malware Turns Minecraft Mods Into a 116,000-System Infostealer Campaign
Cybersecurity

WeedHack Malware Turns Minecraft Mods Into a 116,000-System Infostealer Campaign

WeedHack has infected more than 116,000 systems by targeting Minecraft players through malicious mods, clients, cheats and utilities. McAfee telemetry shows 116,464 affected systems, 2,000 to 3,000 infections a day, more than 240 distribution URLs and 3,820 malicious JAR files. The next signal is whether Minecraft mod communities can move users back toward official download sources before infostealer distribution expands further.

WhatsApp Usernames Hide Phone Numbers But Scam Risk Remains
Cybersecurity

WhatsApp Usernames Hide Phone Numbers But Scam Risk Remains

WhatsApp is rolling out usernames and optional keys to reduce phone-number exposure, but security researchers warn that impersonation and social-engineering scams can move to handles, profile images and trusted-looking accounts.

Merchants See AI Shopping Coming, but Checkout Is Still the Weak Link
Fintech & Digital Payments

Merchants See AI Shopping Coming, but Checkout Is Still the Weak Link

A merchant survey tied to the 2026 Global Digital Shopping Index places the United Arab Emirates in a three-country checkout test. Mobile apps are gaining ground as sales channels, but many merchants still see payment technology, attribution and fraud protection as unfinished work before AI agents start shaping purchases.

Keep Reading

More Stories

Latest
White House Presses PJM Grid Reform As AI Power Demand RisesCloud & Data CentersJul 23, 2026White House Presses PJM Grid Reform As AI Power Demand RisesThe White House warned PJM Interconnection to reform its board governance and stakeholder process as AI data centres and other large loads intensify disputes over grid reliability, electricity prices and infrastructure cost allocation.OpenAI Presence Makes Enterprise AI Agents A Consulting SaleAIJul 22, 2026OpenAI Presence Makes Enterprise AI Agents A Consulting SaleOpenAI’s Presence service is available to eligible enterprise customers through deployed engineers, not as a self-service product, with pricing still scoped individually.Kratos Takedown Leaves Microsoft 365 Session-Theft Risk UnfinishedCybersecurityJul 22, 2026Kratos Takedown Leaves Microsoft 365 Session-Theft Risk UnfinishedGerman and US law enforcement took more than 200 Kratos phishing-kit servers offline, but investigators still tie the service to roughly 1,800 customers and session-theft attacks against Microsoft 365.Augustus Raises $180m For Dollar Rails Across Emerging-Market FintechsFintech & Digital PaymentsJul 22, 2026Augustus Raises $180m For Dollar Rails Across Emerging-Market FintechsAugustus announced a $180 million Series B at a $1 billion valuation, with funding aimed at dollar accounts, payment rails and stablecoin-enabled banking for fintechs and banks across Latin America, Southeast Asia, the Middle East and Africa.China IPv6 Plan Advances Single-Stack Network And Metadata ControlsTelco & ConnectivityJul 22, 2026China IPv6 Plan Advances Single-Stack Network And Metadata ControlsChina is setting 2027 and 2030 IPv6 targets while pushing IPv6+ work that could give carriers more metadata about traffic, raising policy questions for network and cloud buyers outside China.Prysmian Signs $6.29bn Molex Cable Deal For AI Data CentresCloud & Data CentersJul 22, 2026Prysmian Signs $6.29bn Molex Cable Deal For AI Data CentresData Center Dynamics reported that Prysmian’s €5.5 billion Molex agreement includes a €550 million upfront payment and a capacity plan to more than double US fibre output.Spain AI Campus Seeks 300 MW With On-Site Power PlanCloud & Data CentersJul 22, 2026Spain AI Campus Seeks 300 MW With On-Site Power PlanData Center Knowledge reported that EdgeMode, BlackBerry AIF and Mora are seeking regional support for DC MALPICA, a proposed €3 billion ($3.4 billion), 300 MW AI campus whose power model remains partly undisclosed.e& UAE And Core42 Launch Sovereign AI Compute PlatformCloud & Data CentersJul 21, 2026e& UAE And Core42 Launch Sovereign AI Compute PlatformMiddle East AI News reported that e& UAE and Core42 launched Sovereign AI Compute, giving UAE enterprises and government bodies in-country GPU access with data residency, connectivity and vendor-claimed zero egress fees.AI Coding Agents Face Sandbox-Escape Findings Across Four ToolsCybersecurityJul 21, 2026AI Coding Agents Face Sandbox-Escape Findings Across Four ToolsBleepingComputer reported that Pillar Security reproduced sandbox-escape paths in Cursor, OpenAI Codex, Gemini CLI and Google Antigravity, shifting attention from agent containment to trusted developer tools around the workspace.Microsoft Adds AMD Helios AI Racks To Azure Without Order SizeChips & SemiconductorsJul 21, 2026Microsoft Adds AMD Helios AI Racks To Azure Without Order SizeMicrosoft will deploy AMD Helios rack-scale AI accelerators for Azure AI workloads, with watts, dollars and rack counts still absent from the public terms of the commitment.AliExpress Hit With Record €550m EU Fine Over Illegal GoodsCapital & PolicyJul 21, 2026AliExpress Hit With Record €550m EU Fine Over Illegal GoodsBBC reported that the European Commission imposed a record €550m Digital Services Act penalty on AliExpress and ordered the Alibaba-owned marketplace to file a corrective action plan by 20 October.Neo Raises $100M To Control Enterprise AI Software ActionsCybersecurityJul 21, 2026Neo Raises $100M To Control Enterprise AI Software ActionsSecurityWeek reported that Neo emerged from stealth with $100 million for a platform that governs AI agents, MCP servers and software actions across enterprise systems.