Researchers at Purdue, West Point, and Florida International University found Huawei and Yandex code in apps US service members rely on. In April, US Central Command (CENTCOM) confirmed adversaries are exploiting commercial data in the Middle East.
A peer-reviewed study from three US research institutions found that more than one in eight mobile apps marketed to US military personnel contain code from companies based in China, Russia, or other foreign nations. The same sample includes Huawei code inside a popular base-rating app and Yandex advertising tools in two others, according to findings reported this month by the Ars Technica security desk.
The paper, published in the proceedings of the Privacy Enhancing Technologies Symposium (PETS 2026), was produced by researchers at Purdue University, the US Military Academy at West Point, and Florida International University. The team examined hundreds of apps aimed at service members and their families: tools for rating base living conditions, tracking PT scores, finding off-base housing, and connecting with local military communities. The foreign code is not an exotic insertion. It arrives through the same commercial ad-tech and SDK pipeline that powers ordinary consumer apps.
In one case the researchers identified code from Huawei, the Chinese telecom US regulators flagged as a national security threat in 2020, inside an app service members use to rate living conditions on their own bases. Two other apps were built by Russian companies and incorporated Yandex, the Russian internet and advertising firm. Two more apps in the sample were built entirely by Russian developers. The full app list and methodology are available in a public GitHub repository.
The commercial ad-tech supply chain that delivers this code treats service members and civilians the same unless there is profit in telling them apart. A base-rating app and a food-delivery app share the same SDKs, the same bidding layers, the same data brokers, and, in the cases the study documents, the same foreign code. WIRED has previously shown that real-time bidding location data can resolve to specific service members, tracing them to their homes, their children's schools, and the off-base establishments where troops are prohibited from being seen.
In April, US Central Command acknowledged in a letter to Senator Ron Wyden that it had received multiple threat reports of adversaries exploiting commercial location data to target or surveil American personnel in the Middle East. US forces remain locked in a standoff with the Iranian military over the Strait of Hormuz. Lawmakers described the letter as the first official confirmation that troops in an active war zone were being hunted through the data-broker economy, the same commercial pipeline the new study documents inside the apps those troops actually use.
The contractor and academic warnings that produced the letter stretch back nearly a decade. The April letter is the first time the military command responsible for the Middle East has put that warning on the record as an admission to Congress.
The study's authors are careful about what the foreign code does and does not prove. Embedded third-party SDKs and ad networks are not confirmed adversarial access channels. A Huawei analytics component or a Yandex ad SDK is a supply-chain dependency, not a backdoor, and the paper documents presence rather than exploitation. The study establishes that the same unregulated pipeline exposing civilian phone users is, in the cases it flags, also exposing the phones of US service members, while the Pentagon now says adversaries are already working that pipeline against troops in an active war zone.
The April letter does not name a specific adversary or app. The PETS 2026 paper does. Together they describe the same supply chain, and the open question is whether either the ad industry or the Pentagon breaks it before the next confirmation arrives in the form of an incident rather than a study.