top of page

Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds



In early September 2026, cybersecurity researchers identified thirteen malicious Composer theme packages hosted on the official Packagist repository. Published across five distinct vendor namespaces, these libraries masquerade as legitimate, high quality front end themes for popular open source PHP content management systems like OphimCMS and KKPhim, which are widely used to power video streaming and online comic websites. Once an unsuspecting platform administrator installs one of these infected themes, the malicious code automatically begins embedding stealthy JavaScript snippets into every public web page delivered to site visitors.


Multi Stage Exploitation and iOS Kernel Privilege Escalation

The underlying JavaScript engine operates a sophisticated dual track delivery framework designed to profile every incoming user device platform. While general mobile visitors are funneled into automated ad fraud networks and rogue gambling redirect chains, users visiting the compromised websites from unpatched iPhones are targeted with a powerful zero click WebKit to kernel exploit chain. By combining known browser memory corruption vulnerabilities alongside a critical privilege escalation flaw within the Apple graphics driver, the exploit successfully breaks out of the web browser sandbox, grants the attacker deep read and write access at the iOS system kernel level, and deploys a fully functional spyware agent on target devices running iOS 18.4 through 18.6.x.


Direct Financial Exfiltration and Mitigation Recommendations

The ultimate goal of the injected payload is complete identity theft and direct financial exfiltration from infected mobile devices. Once active inside the operating system, the spyware systematically extracts secure keychain records, SMS message databases, saved Wi Fi authentication credentials, personal contact books, stored photos, and active browser session tokens. Recent updates to the threat actor attack infrastructure added dedicated scanning routines designed specifically to locate and extract cryptocurrency wallet seed phrases and recovery mnemonic keys from local storage, directly targeting popular mobile applications such as Trust Wallet, Phantom, Bitget, and OKX. To contain this ecosystem risk, platform operators must immediately audit all third party Composer dependencies, while mobile users must apply the latest iOS security patches to close the underlying WebKit and kernel vulnerabilities.


Reference

 
 
 

Comments


Address: Office B322, Level 3, Spaces, Platinum Sentral, KL Sentral, 50470 Kuala Lumpur.

  • Facebook
  • Instagram
  • LinkedIn

Hotline+60327224705

© 2025 Vardaan Sdn Bhd. All Rights Reserved.

bottom of page