Security researchers discovered that certain smart TV applications contain code capable of turning the TV into a proxy node, allowing external parties to route traffic through a user's home internet connection.
The code, supplied by a data‑collection service, hides processes that continue operating even when the app is closed, giving attackers the ability to use the network for any purpose.
These proxy networks are increasingly employed for cybercrime because they obscure the attacker’s location, enabling traffic originating in one country to appear to come from a home in another.
Several apps on major TV app marketplaces employed simple programs with only a few lines of code that fetched content from remote servers, making them appear legitimate while embedding the proxy functionality.
Both Samsung and LG have responded by removing the offending applications from their official stores after discovering that a substantial portion of listed apps added smart TVs to proxy networks.
Legitimate applications may also include the same data‑collection code, as seen in some licensed game ports, meaning that even well‑known titles can contain the hidden proxy component.
Installing a malicious app does not automatically activate the proxy; activation requires the user to accept a consent prompt, which can turn the TV into a network node.
Users should deny any unexpected permission requests and delete any suspicious or unused apps, which removes the embedded code from the device.
Best practices include reviewing app listings for spelling errors, low‑quality images, and mismatched descriptions, as well as scrutinizing developer histories and user reviews for signs of fraud.
While mainstream streaming services are generally safe, the broader smart TV app ecosystem remains risky, and limiting installations to trusted sources is advisable.