A popular Android app in the Google Play store that is used to make a cartoon character from the user’s photo contains malware and can compromise the user’s Facebook account, according to an article published recently in Bleeping computer, available here https://www.bleepingcomputer.com/news/security/android-password-stealing-malware-infects-100-000-google-play-users/
The malicious app in the Google Play Store, Craftsart Cartoon Photo Tools, asks users to login with their Facebook account in order to use the app.
The login data is then transmitted to the hacker’s computers in Russia, and can be used to login and hack that person’s Facebook account, as explained by a report from the security firm Pradeo security, available here: https://blog.pradeo.com/spyware-facestealer-google-play
Currently, about 100,000 users have been infected, and Google Play Store still has the app available for download.
It is suggested to uninstall the app, and lock down the user’s Facebook account, including adding two-factor authentication to their Facebook login.