<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds]]></title><description><![CDATA[<p dir="auto">Researchers have uncovered a cluster of 13 malicious Composer packages published to Packagist, each disguised as a theme library. These packages are engineered to inject JavaScript into Vietnamese movie and comic streaming platforms that install them, setting off a chain of events targeting visitors’ unpatched iPhones.</p>
<p dir="auto">The injected script performs two distinct operations against site visitors: it redirects users to mobile ad-fraud schemes and gambling pages, while simultaneously attempting to deploy spyware on vulnerable iOS devices. The spyware is specifically crafted to extract cryptocurrency wallet seed phrases from compromised iPhones.</p>
<p dir="auto">Key details from the analysis:</p>
<ul>
<li>13 malicious theme packages were uploaded to Packagist, the official PHP package repository.</li>
<li>The payload targets unpatched iOS devices, meaning iPhones that have not received the latest security updates.</li>
<li>The attack chain begins with the installation of a malicious Composer theme package on a streaming website.</li>
<li>Once live, the injected JavaScript runs dual operations: ad-fraud and gambling redirects, alongside spyware deployment.</li>
<li>The ultimate goal of the spyware is to harvest crypto wallet seeds, giving attackers full control over victims’ digital assets.</li>
</ul>
<p dir="auto">Affected parties should audit any Composer dependencies sourced from Packagist, especially theme packages used in Vietnamese-language streaming services, and verify the integrity of their installed libraries. For iOS users, applying the latest system updates remains a critical defense against this type of exploit chain.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Is your team reviewing Composer package integrity before every deployment, or do you rely on post-install audits to catch malicious dependencies?</p>
]]></description><link>https://xploitlk.com/topic/242/13-malicious-packagist-packages-target-unpatched-iphones-to-steal-crypto-wallet-seeds</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:28:20 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/242.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 06 Sep 2026 22:30:26 GMT</pubDate><ttl>60</ttl></channel></rss>