Google removes nine Play Store apps, including PIP Photo with 5.8M+ downloads, after researchers found the apps were stealing users' Facebook login credentials
delete them now JC Torres / SlashGear : Popular Google Play Store apps removed for stealing Facebook passwords Rob Thubron / TechSpot : Nine apps with 5.8 million downloads kicked from Google Play store for stealing Facebook passwords Duncan Riley / SiliconANGLE : Nine apps stealing Facebook login credentials pulled from Google Play Nehal Malik / iPhone in Canada Blog : Android Apps with 6.5 Million Downloads Stole Facebook Passwords: Study Nathaniel Mott / PCMag : Google Kicks Credential-Stealing Android Apps from the Play Store Paul Lilly / HotHardware.com News : These Malware-Laced Android Apps Are Probably Stealing Your Facebook Password Argam Artashyan / Gizchina : 9 Android Apps Stole Facebook Passwords To Access Other User Data And Accounts Habiba Rashid / HackRead : 9 apps with 6M installs stole Facebook logins of Android users Alyse Stanley / Gizmodo : These Nine Android Apps May Have Stolen Your Facebook Login Information Alan Friedman / PhoneArena : These Android apps appear normal but steal your Facebook password; uninstall them immediately Chris Smith / BGR : These 9 Android apps might have stolen your Facebook password Tweets: Alex Russell / @slightlylate : At the bottom of this security issue is an OS choice to allow native apps to disrespect user choice of browser, and suborning developer intent on pages that would otherwise opt out of “in app browsers”. This one is on Android. Tuna Toksoz / @tehlike : @alexbilz @GeorgeBevis @rabois https://arstechnica.com/... Another one. All you need is to show a page inside an app and ask their password for some confidential stuff. People just give it. This is also why 2fa is important. Michael Love / @elkmovie : Apps which were in their store + had passed human (not ‘largely automated’ - it takes longer than Apple!) app review. Yet somehow sideloading is the reason Android has so much malware. https://twitter.com/... I.Zhilyakov / @m0br3v : Android Trojans that steal Facebook users' usernames, passwords and cookies were found on Google Play. They load the legitimate Facebook webpage into WebView. Then they load JS received from the C&C into the same WebView. https://news.drweb.com/... IoCs: https://github.com/... https://twitter.com/... Paolo Campisi / @pcampisi14 : I stopped coding and writing scripts in 2013, at that time the Facebook Access Token was the holy grail of shit you didn't want to expose, once someone had it you were fucked. I wonder if it's still the case. https://twitter.com/... @howtomen : If you downloaded any of these Android apps, CHANGE YOUR FACEBOOK PASSWORD NOW! These sneaky devs used a script from JavaScript to hijack the entered login credentials when they loaded up Facebook's login page on WebView. Apps are no long on the play store thankfully. SCARY!! https://twitter.com/... https://twitter.com/...
Context & Ripple Effects
Google’s removal follows a recurring Play Store enforcement pattern: researchers had already identified 25 Android apps using Facebook credential phishing overlays, and Google had also removed apps tied to scam ads. The new case shows that large download counts have not prevented credential-theft apps from reaching users through the store.
The immediate issue is not merely malicious functionality but distribution: apps presenting ordinary utility features can use Play Store reach to solicit Facebook credentials before researchers trigger a takedown.
First-order effects
- Google removes the nine identified apps from Play Store distribution, while users who entered Facebook credentials into them face an account-security problem.
- Facebook is the credential target in the reported campaign, making affected users’ Facebook logins the immediate asset exposed by the apps.
Second-order effects
- Google’s app-review and post-publication enforcement process faces added pressure because the earlier Facebook-phishing app removals did not stop a subsequent, higher-download campaign.
- Android utility-app publishers face more scrutiny around embedded login flows and WebView behavior, since seemingly routine app categories have been used to collect credentials.
Third-order effects
- Repeated researcher-led removals point to Play Store governance becoming a continuing detection-and-takedown cycle rather than a one-time screening decision.
- If credential theft keeps appearing in broadly distributed apps, trust in platform-controlled software delivery will depend increasingly on faster monitoring of apps after installation, not only admission checks.
The trend: Mobile app stores are becoming a persistent security control point as credential-phishing campaigns repeatedly exploit the distribution reach of ordinary-looking Android apps.