CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5802

As cited

Copy frozen at (site build).

vulnerabilities

13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds

Socket's Threat Research Team discovered 13 malicious Composer theme packages distributed across five vendor namespaces on Packagist that inject JavaScript into Vietnamese streaming sites. On mobile devices, the injected code triggers ad fraud and gambling redirects, while on iPhones running iOS 18.6.x or earlier, it delivers a WebKit-to-kernel exploit chain that harvests keychain data, wallet seeds, and device information. The operators redeployed the entire payload chain on August 12, 2026, and August 17, 2026, expanding the spyware to steal cryptocurrency wallet seeds from seven popular wallet applications.

Why it matters: Site operators running OphimCMS or KKPhim who installed these trojanized themes are unknowingly serving spyware to mobile visitors; iPhone users on iOS 18.6.x or earlier who visit these sites risk complete device compromise including financial theft. Security teams should block the infrastructure domains, hunt for the network indicators and wallet-theft routines, and prioritize updating iPhones off iOS 18.6.x and earlier, as the exploited WebKit vulnerabilities and kernel escape were fixed in iOS 26.1 and later versions.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds

Socket's Threat Research Team discovered 13 malicious Composer theme packages distributed across five vendor namespaces on Packagist that inject JavaScript into Vietnamese streaming sites. On mobile devices, the injected code triggers ad fraud and gambling redirects, while on iPhones running iOS 18.6.x or earlier, it delivers a WebKit-to-kernel exploit chain that harvests keychain data, wallet seeds, and device information. The operators redeployed the entire payload chain on August 12, 2026, and August 17, 2026, expanding the spyware to steal cryptocurrency wallet seeds from seven popular wallet applications.

Why it matters: Site operators running OphimCMS or KKPhim who installed these trojanized themes are unknowingly serving spyware to mobile visitors; iPhone users on iOS 18.6.x or earlier who visit these sites risk complete device compromise including financial theft. Security teams should block the infrastructure domains, hunt for the network indicators and wallet-theft routines, and prioritize updating iPhones off iOS 18.6.x and earlier, as the exploited WebKit vulnerabilities and kernel escape were fixed in iOS 26.1 and later versions.

VendorsAppleGoogleGitHubCloudflare
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary