Study reveals Chinese and Russian code embedded in apps marketed to US troops
Analysis of over 220 apps shows nearly two-thirds contain third-party code, with approximately 7 percent originating from nations designated as adversaries by the Pentagon.

A joint analysis by researchers from Purdue University, the US Military Academy at West Point, and Florida International University has identified that more than one in eight apps marketed to US service members contain software code from companies in China, Russia, or other foreign nations. The study examined over 220 applications, including those for banking, dating, and uniform guides, sourced from the Google Play store and military subreddits. Approximately 7 percent of the apps contained third-party code from nations designated as adversaries by the Pentagon, including Huawei (China) and firms linked to Yandex (Russia). This finding follows an April admission by US Central Command that adversaries have exploited commercial location data to target US personnel in the Middle East.
The research, led by Purdue University PhD researcher Joshua Shinkle, highlights significant privacy vulnerabilities within the digital tools used by the military. The team found that nearly two-thirds of the 220 apps analysed contained third-party code, known as software development kits (SDKs), which are typically used for analytics and advertising but can also track user behaviour and share information with outside companies. Forty percent of the apps collected or shared more data than they disclosed in their Google or Apple store listings. While the most common SDKs came from Google and Facebook, 76 apps contained code traced back to China, Russia, Israel, India, and Germany.
Of particular concern were twelve apps that contained HMS Core, a Huawei software kit capable of mapping user locations, delivering ads, and storing media. Several of these applications were built for state National Guard organisations. Although researchers observed no data being transmitted to Huawei servers in the sampled instances, experts warn that dormant SDKs could be updated remotely to harvest sensitive location and deployment data. In at least one case, the Huawei code arrived without the app’s developer’s knowledge, smuggled in as a dependency in a commercial notification tool.
The stakes of this data exposure are no longer theoretical. In April, US Central Command acknowledged in correspondence with Senator Ron Wyden that it had received multiple threat reports of adversaries exploiting commercial location data to target or surveil American personnel in the Middle East. This admission followed nearly a decade of warnings from Pentagon contractors and researchers about the threat of data-broker exploitation. Previous investigations have shown that location data from ordinary apps can reveal the homes, children's schools, and off-base locations of US service members, potentially aiding foreign spies in identifying personnel with access to sensitive sites.
A survey of 103 military-affiliated individuals revealed that 83 percent used at least one app with data practices they found uncomfortable, and 76–83 percent were extremely uncomfortable with apps containing code from China, Russia, Iran, or North Korea. Participants ranked in-phone warnings about foreign third-party code as the most effective mitigation, alongside support for federal laws restricting data brokers and stricter bans on foreign code. The study underscores the lack of transparency, as neither Google's Play Store Data Safety section nor Apple's App Store Privacy Labels disclose the country of origin of the software running inside an app.