As cited
Copy frozen at (site build).
vulnerabilities
13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds
Socket's Threat Research Team discovered 13 malicious Composer theme packages distributed across five vendor namespaces on Packagist that inject JavaScript into Vietnamese streaming sites. On mobile devices, the injected code triggers ad fraud and gambling redirects, while on iPhones running iOS 18.6.x or earlier, it delivers a WebKit-to-kernel exploit chain that harvests keychain data, wallet seeds, and device information. The operators redeployed the entire payload chain on August 12, 2026, and August 17, 2026, expanding the spyware to steal cryptocurrency wallet seeds from seven popular wallet applications.
Why it matters: Site operators running OphimCMS or KKPhim who installed these trojanized themes are unknowingly serving spyware to mobile visitors; iPhone users on iOS 18.6.x or earlier who visit these sites risk complete device compromise including financial theft. Security teams should block the infrastructure domains, hunt for the network indicators and wallet-theft routines, and prioritize updating iPhones off iOS 18.6.x and earlier, as the exploited WebKit vulnerabilities and kernel escape were fixed in iOS 26.1 and later versions.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds
Socket's Threat Research Team discovered 13 malicious Composer theme packages distributed across five vendor namespaces on Packagist that inject JavaScript into Vietnamese streaming sites. On mobile devices, the injected code triggers ad fraud and gambling redirects, while on iPhones running iOS 18.6.x or earlier, it delivers a WebKit-to-kernel exploit chain that harvests keychain data, wallet seeds, and device information. The operators redeployed the entire payload chain on August 12, 2026, and August 17, 2026, expanding the spyware to steal cryptocurrency wallet seeds from seven popular wallet applications.
Why it matters: Site operators running OphimCMS or KKPhim who installed these trojanized themes are unknowingly serving spyware to mobile visitors; iPhone users on iOS 18.6.x or earlier who visit these sites risk complete device compromise including financial theft. Security teams should block the infrastructure domains, hunt for the network indicators and wallet-theft routines, and prioritize updating iPhones off iOS 18.6.x and earlier, as the exploited WebKit vulnerabilities and kernel escape were fixed in iOS 26.1 and later versions.
- Source published
- First seen by Cybersecurity Tracker