Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious Packages Target iPhones for Crypto Theft

Malicious Packages Target iPhones for Crypto Theft

Posted on September 1, 2026 By CWS

Cybersecurity experts have recently uncovered a series of 13 malicious packages on Packagist, specifically designed to inject harmful JavaScript into Vietnamese movie and comic streaming platforms. These packages target unpatched iPhones, deploying spyware to extract sensitive information, including cryptocurrency wallet seeds.

How the Malicious Packages Operate

The threat is executed by injecting code that performs two main operations: redirecting mobile traffic for ad-fraud and gambling, and exploiting iPhones through a WebKit-to-kernel chain to install spyware. This was highlighted by security researcher Kush Pandya from Socket. The campaign traces back to March 2026, initially involving six Packagist packages masquerading as OphimCMS themes, which rerouted traffic and exfiltrated data.

The affected packages span across multiple namespaces including vsmov, vsphim, haiau009, chilltvcms, and ophimcms. These trojanized themes inject scripts that lead to spyware installations, ultimately resulting in the theft of cryptocurrency wallet information.

Details of the iOS Exploit Chain

The exploitation method involves inserting a hidden iframe to identify the iOS version and load a corresponding exploit. This attack leverages two known WebKit vulnerabilities, CVE-2025-31277 and CVE-2025-43529, akin to the techniques used in the DarkSword exploit kit. Apple has since patched these vulnerabilities in later iOS versions.

Once the attack is successful, the spyware gains access to the device’s kernel, allowing it to extract and encrypt sensitive data such as keychain databases, SMS logs, and browser cookies, which are then uploaded to remote servers.

Implications and Preventative Measures

The campaign saw a resurgence on August 12, 2026, with a new payload specifically targeting iOS devices with versions between 18.4 and 18.6.x. This payload seeks out cryptocurrency wallet data from several wallet apps, widening the impact from data theft to direct financial losses.

Despite the malicious nature of these packages, some additional theme packages published by the same vendors were found without active payloads but could be activated through specific site configurations. The campaign is suspected to be run by a Vietnamese group, with infrastructure linked to the sanctioned entity Funnull.

Website operators using sensitive themes like OphimCMS or KKPhim are urged to verify their installations, remove any suspicious packages, and conduct thorough security audits to mitigate potential threats. Regular updates and a vigilant approach to cybersecurity can help protect against such vulnerabilities.

The Hacker News Tags:crypto theft, Cybersecurity, iOS exploit, iPhone, JavaScript injection, malicious packages, OphimCMS themes, Packagist, Spyware, WebKit vulnerabilities

Post navigation

Previous Post: Five Hackers Admit to ATM Malware Attacks in Kansas
Next Post: WatchGuard Addresses Critical Security Flaws in Fireware OS

Related Posts

Featured Chrome Browser Extension Caught Intercepting Millions of Users’ AI Chats Featured Chrome Browser Extension Caught Intercepting Millions of Users’ AI Chats The Hacker News
AI Agents Are Becoming Privilege Escalation Paths AI Agents Are Becoming Privilege Escalation Paths The Hacker News
New HTTP/2 Bomb Exploit Threatens Major Web Servers New HTTP/2 Bomb Exploit Threatens Major Web Servers The Hacker News
Researchers Warn of Self-Spreading WhatsApp Malware Named SORVEPOTEL Researchers Warn of Self-Spreading WhatsApp Malware Named SORVEPOTEL The Hacker News
Critical Cisco Vulnerability in Unified CM Grants Root Access via Static Credentials Critical Cisco Vulnerability in Unified CM Grants Root Access via Static Credentials The Hacker News
Adapting Security Strategies for Near-Zero Exploit Windows Adapting Security Strategies for Near-Zero Exploit Windows The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cloud Services Misused to Conceal Phishing in Finance
  • Critical Exploits Target Langflow and Ruby on Rails Systems
  • WatchGuard Addresses Critical Security Flaws in Fireware OS
  • Malicious Packages Target iPhones for Crypto Theft
  • Five Hackers Admit to ATM Malware Attacks in Kansas

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cloud Services Misused to Conceal Phishing in Finance
  • Critical Exploits Target Langflow and Ruby on Rails Systems
  • WatchGuard Addresses Critical Security Flaws in Fireware OS
  • Malicious Packages Target iPhones for Crypto Theft
  • Five Hackers Admit to ATM Malware Attacks in Kansas

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark