Close Menu
NCIJ Network NCIJ Network
    What's Hot

    U.S. Launches Strikes in Iran Targeting IRGC

    September 1, 2026

    Listening to households: expectations, behaviour and monetary policy

    September 1, 2026

    Sonos Ace Ultra, Beam Ultra, Sonos Fabric, and a New App: Everything Sonos Just Announced

    September 1, 2026
    Facebook X (Twitter) Instagram
    Trending
    • U.S. Launches Strikes in Iran Targeting IRGC
    • Listening to households: expectations, behaviour and monetary policy
    • Sonos Ace Ultra, Beam Ultra, Sonos Fabric, and a New App: Everything Sonos Just Announced
    • 13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
    • 21 Financial Giants Form Venture for G7 Stablecoins
    • The universe may have been building rocky planets almost from the start
    • Eagle LNG draws $30M Datacentrex bet as US space launch boom accelerates
    • Your Right to Know: Let the public copy court records
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 1
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 1, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices.

    “The injected code runs two operations against a site’s visitors: a mobile ad-fraud and gambling-redirect chain, and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware,” Socket security researcher Kush Pandya said.

    The activity is assessed to be part of a campaign that was first documented by the application security company back in March 2026 that leveraged six malicious Packagist packages posing as OphimCMS themes to redirect visitors, exfiltrate URLs, inject ads, and serve from Funnull-hosted infrastructure a second-stage payload to lead victims to gambling and adult content sites.

    Cybersecurity

    The complete set of packages, which span five vendor namespaces, is below –

    • vsmov: theme-dy, theme-rrdyw, theme-motchill, theme-vsmov
    • vsphim: theme-heovl, theme-thempho
    • haiau009: kkphim-legend, kkphim-motchill
    • chilltvcms: theme-legend
    • ophimcms: theme-dy, theme-motchill, theme-pcc, theme-rrdyw

    At a high level, the trojanized Composer theme injects JavaScript that runs a mobile gambling and ad-fraud redirect and, on iPhones, a Funnull-hosted WebKit-to-kernel exploit chain ending in spyware and cryptocurrency-wallet theft.

    The iOS attack chain is designed to insert a hidden iframe element that determines the iOS version and loads an operating system-specific version of the exploit. Specifically, it weaponizes two WebKit vulnerabilities — CVE-2025-31277 (Patched in version 18.6) and CVE-2025-43529 (Patched in versions 18.7.3 and 26.2) — in a manner that’s analogous to the DarkSword exploit kit.

    The payload then pivots out of the WebContent sandbox into the GPU process, followed by a second stage that reaches the kernel through the AppleM2ScalerCSCDriver IOKit user client and ultimately obtains read and write privileges. Apple is said to have addressed the kernel escape flaw in iOS and macOS 26.1.

    Pandya told The Hacker News that Apple did not share a CVE identifier for the kernel escape vulnerability, but that the iPhone maker confirmed the issue had already been patched in iOS 26.1 and macOS 26.1 before receiving their report. It’s suspected to be CVE-2025-43398, CVE-2025-43510, or CVE-2025-43520, all of which were kernel-related bugs fixed late last year.

    “On success, the final payload uses the kernel read to collect keychain databases, Wi-Fi passwords, the SMS database, the address book, Photos, browser cookies, call history, location history, and account databases, encrypts them with AES, and uploads them over HTTPS POST /upload to a rotating pool of command and control domains,” Pandya explained. “The worker beacons exploitation progress to cloudfareintcdn[.]com/wd-status.html.”

    The threat actors behind the campaign have been found to redeploy the whole iOS chain around August 12, 2026, mainly targeting iOS devices running versions 18.4 through 18.6.x with a new payload that adds an iOS Keychain cryptocurrency wallet seed and mnemonic stealer.

    The malware queries the password store for wallet material from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX, extending beyond device data collection to direct financial theft.

    Socket said the same five vendor namespaces have published additional theme packages that carry no active payload at the time of analysis, although they have been configured such that the malicious code could be activated via “Custom JS” fields rendered into every page on the websites.

    Cybersecurity

    It’s not clear who is behind the campaign, although it’s believed to be the work of a Vietnamese-operated group based on commit metadata timestamps. It’s worth pointing out that the iOS exploit hosts run on infrastructure provided by Funnull, an entity sanctioned by the U.S. last May for facilitating romance baiting scams that led to over $200 million in cryptocurrency losses.

    “A visitor to a site that installed one of these themes, on an iPhone that has not been updated past iOS 18.6.x (iPhone XS through iPhone 16), can have their keychain, Wi-Fi passwords, SMS, Photos, contacts, cookies, location history, account databases, and cryptocurrency wallet seeds collected and exfiltrated by loading a page in mobile Safari,” Socket said.

    “Every mobile visitor is also subject to the gambling-redirect and ad-injection chain. The site operators are victims too: they shipped the trojanized theme unknowingly and served the payload to their own users.”

    To counter the threat, site operators using OphimCMS or KKPhim are advised to check if they have installed any of the aforementioned packages, remove them if found, rotate credentials, and audit shipped jQuery and theme scripts for indicators of compromise.

    Crypto iPhones Malicious Packages Packagist Seeds Steal Target unpatched Wallet
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Novocure data breach affects more than 1,400 cancer patients

    Hackers push malicious Virtualizor update in BGP hijacking attack

    Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

    Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

    Hackers Start Exploiting Critical Langflow Vulnerability

    Russia just switched on a crypto market that doesn’t fully exist yet

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    U.S. Launches Strikes in Iran Targeting IRGC

    September 1, 2026

    Listening to households: expectations, behaviour and monetary policy

    September 1, 2026

    Sonos Ace Ultra, Beam Ultra, Sonos Fabric, and a New App: Everything Sonos Just Announced

    September 1, 2026

    13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

    September 1, 2026
    Latest Posts

    Bitcoin Only Makes Up 1% Of Legendary Investor Ray Dalio’s Portfolio

    July 30, 2026

    AI Harnesses Burst With Potential Exploit Opps

    July 30, 2026

    LinkedIn actually adds a ‘seems like AI slop’ button

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    U.S. Launches Strikes in Iran Targeting IRGC

    September 1, 2026

    Listening to households: expectations, behaviour and monetary policy

    September 1, 2026

    Sonos Ace Ultra, Beam Ultra, Sonos Fabric, and a New App: Everything Sonos Just Announced

    September 1, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.