But this explains the explosion of bot traffic that really cripples a lot of smaller services (like my forgejo instance, that I had to make non-public).
So if you include such an SDK in your app to make some money — you are part of the problem and I think you should be punished for that. You are delivering malware to your users, making them botnet members.
Unfortunately it is next to impossible for normal users to detect the inclusion of such shady SDKs and the network traffic they cause.
4/8