It sounds like a great deal: a $20 or $30 streaming stick that turns any television into a smart TV. But KrebsOnSecurity is warning consumers that a growing number of these low-cost Android-based devices — sold through major online marketplaces — are arriving with malware already embedded in their firmware, before a buyer even opens the box. This is not a hypothetical threat. Researchers have confirmed active, preinstalled malicious software on devices being shipped and delivered to real customers right now. If you are shopping for a budget streaming gadget, the threat landscape around identity security and device compromise has shifted enough that this purchase deserves a harder look than you might expect.
The devices flagged in the KrebsOnSecurity report are inexpensive Android TV sticks sold under generic or little-known brand names, often fulfilled through third-party sellers on platforms like Amazon. Security researchers found that the malicious code is not something a user downloads accidentally — it is baked directly into the operating system image that ships on the hardware. Once plugged in and connected to a home network, these sticks can phone home to remote command-and-control servers, participate in ad fraud schemes, and potentially expose other devices on the same Wi-Fi network to further compromise.

Malware That Arrives Before You Even Log In
What makes this attack vector particularly insidious is that there is no user error involved. Traditional malware warnings tell you not to click suspicious links or download unknown apps. Here, the infection is factory-installed. Researchers found that the firmware on affected sticks contains trojanized system apps — code that runs with elevated privileges and cannot be removed through standard user-facing settings. Because these apps sit at the operating system level, a factory reset does not eliminate them. The malware persists through reboots and conventional cleanup attempts.
The specific threat identified in the KrebsOnSecurity investigation connects to a broader family of Android TV firmware backdoors that security researchers have been tracking for several years, with threat actors using compromised devices to build residential proxy networks. Those networks are then rented out to other criminals who want to route malicious traffic through what appears to be ordinary household internet connections. Your living room device, in other words, becomes infrastructure for someone else’s fraud operation — without any visible sign to you that anything is wrong.
What to Buy Instead — and What to Check Before You Plug Anything In
The clearest advice from security researchers is to stick with devices made by established, name-brand manufacturers whose firmware supply chains are more tightly controlled. Products from Google, Amazon, Apple, and Roku have dedicated security teams and receive regular, verified software updates. The risk calculus on a $25 no-name Android stick from an unknown third-party seller is simply not worth the savings. If you want to avoid smart TV software ecosystems entirely, there are compelling alternatives: The Verge recently noted in its Vizio TV review that the display effectively functions as a premium dumb TV when paired with a trusted external streaming device, giving users more control over what software is running on their network.

For shoppers drawn to value-priced televisions with integrated smart features, the picture is not uniformly bleak — it just requires being selective. Business Insider’s hands-on TCL QM7L review highlights how a midrange set from a well-established brand can deliver near-premium performance without forcing buyers toward unvetted third-party hardware. The lesson is the same whether you are buying a TV or a streaming stick: brand provenance and firmware accountability matter far more than the sticker price. A device that costs less upfront but quietly joins a botnet the moment it hits your home network is not a bargain by any measure. Check the seller, verify the brand has a real support presence, and when in doubt, spend a little more for hardware from a company that has something to lose if its software gets caught doing something criminal.
The cybersecurity industry has long warned that the expanding universe of low-cost connected devices represents one of the most poorly secured attack surfaces in consumer technology. Preinstalled malware on streaming sticks is a stark confirmation of that warning arriving in living rooms across the country. Treat your television’s HDMI port with at least as much skepticism as you would a USB drive handed to you by a stranger.
