Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Vulnerabilities & CVEs
  5. 13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

Scheduled Pinned Locked Moved Vulnerabilities & CVEs
ios
1 Posts 1 Posters 9 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Researchers have uncovered a cluster of 13 malicious Composer packages published to Packagist, each disguised as a theme library. These packages are engineered to inject JavaScript into Vietnamese movie and comic streaming platforms that install them, setting off a chain of events targeting visitors’ unpatched iPhones.

    The injected script performs two distinct operations against site visitors: it redirects users to mobile ad-fraud schemes and gambling pages, while simultaneously attempting to deploy spyware on vulnerable iOS devices. The spyware is specifically crafted to extract cryptocurrency wallet seed phrases from compromised iPhones.

    Key details from the analysis:

    • 13 malicious theme packages were uploaded to Packagist, the official PHP package repository.
    • The payload targets unpatched iOS devices, meaning iPhones that have not received the latest security updates.
    • The attack chain begins with the installation of a malicious Composer theme package on a streaming website.
    • Once live, the injected JavaScript runs dual operations: ad-fraud and gambling redirects, alongside spyware deployment.
    • The ultimate goal of the spyware is to harvest crypto wallet seeds, giving attackers full control over victims’ digital assets.

    Affected parties should audit any Composer dependencies sourced from Packagist, especially theme packages used in Vietnamese-language streaming services, and verify the integrity of their installed libraries. For iOS users, applying the latest system updates remains a critical defense against this type of exploit chain.

    Source: The Hacker News

    Is your team reviewing Composer package integrity before every deployment, or do you rely on post-install audits to catch malicious dependencies?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World