HackMyIP
← Back to News
2026-09-01 The Hacker News

Malicious Packagist Themes Exploit WebKit to Steal iPhone Crypto Wallets

MalwareSupply ChainZero-Day

Socket security researcher Kush Pandya has uncovered 13 malicious Composer theme packages on Packagist that target unpatched iPhones, ultimately stealing cryptocurrency wallet seeds alongside extensive personal data. The trojanized packages, spread across five vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, and ophimcms), masquerade as Vietnamese movie and comic streaming site themes for OphimCMS. This represents an escalation of activity first documented by Socket in March 2026, which initially leveraged six similar packages to redirect visitors, exfiltrate URLs, and inject ads via Funnull-hosted infrastructure.

The attack chain begins when streaming sites install these malicious packages, injecting JavaScript that performs mobile ad-fraud and gambling redirects on all visitors. For iPhone users on unpatched iOS versions, a separate WebKit-to-kernel exploit chain activates inside a hidden iframe that selects OS-specific payloads. The campaign weaponizes two WebKit vulnerabilities—CVE-2025-31277 (patched in iOS 18.6) and CVE-2025-43529 (patched in iOS 18.7.3 and 26.2)—in a manner analogous to the DarkSword exploit kit. The payload pivots from the WebContent sandbox into the GPU process, then exploits an AppleM2ScalerCSCDriver IOKit user client flaw—suspected to be CVE-2025-43398, CVE-2025-43510, or CVE-2025-43520, all patched in iOS and macOS 26.1—to escape to the kernel and obtain read/write privileges.

Once kernel access is achieved, the final payload harvests keychain databases, Wi-Fi passwords, SMS messages, address books, photos, browser cookies, call history, location history, and account databases. This stolen data is encrypted with AES and exfiltrated via HTTPS POST requests to a rotating pool of command-and-control domains, while exploitation status beacons are sent to cloudfareintcdn[.]com/wd-status.html. Apple confirmed the kernel escape flaw was addressed in iOS 26.1 and macOS 26.1 prior to receiving Pandya's report, though no CVE was assigned by the company.

Defenders investigating this campaign and similar supply-chain threats should examine suspicious infrastructure with a WHOIS lookup on any flagged C2 domains, while end users concerned about data exposure can run a comprehensive privacy checkup to identify leaked credentials. Because the exfiltration relies on outbound network communication, a DNS leak test can also help confirm whether DNS queries are being routed through unintended resolvers—a critical check when analyzing devices potentially targeted by similar spyware operations.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →