1 in 8 targeted military apps hide foreign code from China and Russia
Ars review finds Huawei and Yandex components in popular troop-facing apps, turning “just advertising” into a security problem.

Researchers at Purdue University, the US Military Academy at West Point, and Florida International University examined hundreds of mobile apps marketed to US service members. They found more than one in eight contained software built by companies in China, Russia, or other foreign nations, including Huawei code in a popular base-rating app and Yandex ad service code in two others.
More than one in eight mobile apps marketed to US military personnel contained foreign code, according to research by Purdue University, the US Military Academy at West Point, and Florida International University. That is not a theoretical risk. It is a measurable property of apps that service members may download, use, and trust for everyday functions tied to where they live, work, and deploy.
In the researchers' review, one popular app used by service members to rate living conditions on their own bases included code from Huawei, the Chinese telecom flagged by US regulators as a national security threat in 2020. Two other apps were built by Russian companies and incorporated the Russian ad service Yandex. Those are the specific names that matter because they connect the “foreign code” label to real-world software supply chains, known vendors, and existing regulatory attention.
The deeper issue is less about a single app and more about how incentives work in mobile software. The researchers point to the largely unregulated advertising industry that tracks Americans online, treating civilians and service members mostly the same unless there is profit in separating them. If data collection and ad targeting can be tuned to different audiences, the same infrastructure can also be used to infer different operational contexts. And when that ad and tracking ecosystem runs inside apps used by service members, it effectively rides along with the mission.
Why does that matter for deployment-level security? Because exposure can reveal troop deployments, unit movements, and the routines of personnel within intelligence facilities and hardened shelters where nuclear weapons are believed to be stored. That is the chain the researchers are flagging: foreign code plus tracking plus operationally sensitive routines equals a potential pathway for adversary governments to harvest data about where service members are, what they are doing, and how they move.
This also sits awkwardly with how many people, and many procurement workflows, think about “apps.” Service members are often users of consumer-style tools, and advertisers often build measurement systems that do not care whether the person in front of them is a civilian or in uniform. The source frames a blunt reality: if the ad market does not reliably distinguish between those groups, then security assumptions based on audience type can fail. In other words, the app category and the ad category can both look ordinary until you connect the dots.
There is a regulatory background that makes the Huawei detail especially pointed. US regulators flagged Huawei as a national security threat in 2020. Seeing Huawei code inside an app used by service members to rate living conditions on their bases suggests that at least some foreign-risk software is still flowing into the field through routes that may be overlooked by traditional security checks. For boards and executives, the implication is uncomfortable but practical: compliance with “we block the obvious vendors” is not enough if unvetted components arrive through ad SDKs, analytics libraries, or other embedded dependencies.
The Yandex finding raises a parallel concern. Two apps built by Russian companies incorporated the Russian ad service Yandex. Even without claiming intent, the presence of known ad infrastructure matters because advertising stacks are designed to collect signals, measure behavior, and deliver targeted content. When those systems live inside apps used by service members, the measurement becomes a surveillance opportunity, especially when combined with location, time, and routine patterns.
The strategic stakes for decision-makers are the same whether you are overseeing military-adjacent products or consumer apps with any overlap to sensitive users. This research is a warning that foreign code can enter through mainstream channels. It also raises governance questions for enterprises: Who owns third-party code review? How often are dependencies audited? How do you test for tracking or vendor SDKs inside “everyday” apps? If a baseline of more than one in eight exists in a sample of hundreds, then the odds are not comforting for any organization assuming that “popular app” automatically means “safe app.”
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology

By 2035, data centers could use 4x more electricity than today
A new build pipeline through 2033 may consume power on par with India, forcing operators to plan for scarcity now.
Frozen-fiber tech couples light and sound 1,000x more strongly than standard glass
A glass capillary frozen into a fiber lets photonic systems trade energy waste for tighter light-sound linkage.
Nvidia publishes Vera AI server CPU specs, posting SPEC CPU 2026 integer lead over AMD
The company released a white paper with SPEC CPU 2026 results, placing Vera ahead of AMD's Epyc 9755 for integer performance.

