← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • 13 malicious Composer packages found on Packagist.
  • Packages inject JavaScript for ad-fraud and iOS spyware deployment.
  • Spyware targets unpatched iPhones to steal crypto wallet seeds.
  • Exploits WebKit vulnerabilities CVE-2025-31277 and CVE-2025-43529.

Discovery of Malicious Packages

Cybersecurity researchers have uncovered 13 malicious Composer theme packages hosted on Packagist. These packages are designed to be installed by Vietnamese movie and comic streaming sites. Once installed, they inject JavaScript code into these websites, which then targets visitors.

Attack Mechanism and Targets

The injected JavaScript performs two main operations: it initiates a mobile ad-fraud and gambling-redirect chain, and for iPhone users, it deploys a WebKit-to-kernel exploit chain to install spyware. This activity is part of an ongoing campaign first documented in March 2026, which previously used six malicious Packagist packages to redirect visitors and serve gambling/adult content.

The complete set of identified packages spans five vendor namespaces: vsmov, vsphim, haiau009, chilltvcms, and ophimcms. These packages are trojanized Composer themes that ultimately lead to spyware and cryptocurrency-wallet theft on iPhones.

iOS Exploit Chain Details

The iOS attack chain inserts a hidden iframe to determine the iOS version and load a specific exploit. It weaponizes two WebKit vulnerabilities, CVE-2025-31277 (patched in version 18.6) and CVE-2025-43529 (patched in versions 18.7.3 and 26.2), similar to the DarkSword exploit kit. The payload then escapes the WebContent sandbox into the GPU process.

A second stage of the attack reaches the kernel through the AppleM2ScalerCSCDriver IOKit user client, ultimately obtaining read and write privileges. Apple reportedly addressed this kernel escape flaw in iOS and macOS 26.1.

Data Exfiltration

Upon successful exploitation, the final payload uses kernel read capabilities to collect sensitive data. This includes keychain databases, Wi-Fi passwords, SMS databases, address books, Photos, browser cookies, call history, location history, and account databases. This collected data is then encrypted with AES and uploaded via HTTPS POST to a rotating pool of command and control domains.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~24 min · 20 stories · Sep 01

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Cybersecurity researchers identified 13 malicious Composer theme packages on Packagist that inject JavaScript into websites, deploying spyware on unpatched iOS devices to steal cryptocurrency wallet seeds and other sensitive data. This campaign leverages WebKit vulnerabilities and a kernel escape flaw to gain read and write privileges on affected iPhones.