Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Website Themes to Steal iPhone Crypto Data

Hackers Exploit Website Themes to Steal iPhone Crypto Data

Posted on September 1, 2026 By CWS

In a sophisticated cyberattack, hackers are targeting iPhone users by embedding malicious code into website themes, transforming ordinary visits into opportunities for cryptocurrency theft and spyware infiltration. This alarming trend, identified by Socket.dev and reported to Cyber Security News, exploits themes used on Vietnamese streaming sites, catching users unawares.

Method of Attack

The attack vector involves compromised themes installed through Composer, a tool widely used for adding components to websites. Once these themes are adopted by site operators, every visitor to the site is exposed to potential risks. While mobile users may be redirected to gambling sites, iPhone users face more severe threats, as the malicious code appears on seemingly legitimate streaming platforms.

Socket.dev’s research uncovered 13 compromised theme packages, revealing how easily a front-end theme can become a silent attack vector. The threat extends to site operators, who may unknowingly expose user data and wallet recovery information, echoing past npm package compromises.

Technical Exploits and Vulnerabilities

The altered themes contain JavaScript loaders that assess the visitor’s device and referral source, bypassing desktop browsers and automated scanners. For mobile users, the attack injects ads and redirects browsers to gambling sites. However, iPhone users face a more targeted approach, where the script exploits known WebKit vulnerabilities to gain deeper device access.

Apple has addressed these vulnerabilities, emphasizing the importance of updating to the latest iOS versions. Devices on outdated software remain vulnerable, as the attack chain targets specific iOS versions.

Impact on iPhone Users

Once access is established, the spyware collects sensitive data, including keychain contents, Wi-Fi passwords, and cryptocurrency wallet seed phrases. This data is encrypted and sent to a rotating set of command-and-control servers, making detection challenging. The attack’s focus on wallet seed phrases poses a significant financial risk, as these codes can grant attackers control over cryptocurrency funds.

The attackers update filenames and components frequently, complicating detection and takedown efforts. This tactic is reminiscent of other package ecosystem threats, where seemingly benign updates hide malicious intentions.

Protective Measures and Recommendations

Website operators using affected content management systems should scrutinize themes, update front-end scripts, and monitor network activity for signs of compromise. Developers are advised to review Composer dependencies rigorously. Security teams should block network indicators and prioritize iPhone updates to mitigate risks.

This campaign serves as a stark reminder of the dangers posed by software supply chain attacks, affecting not only developers but also end-users visiting compromised sites. Staying vigilant and maintaining up-to-date software are crucial steps in protecting against such threats.

Cyber Security News Tags:Composer, crypto theft, cryptocurrency wallets, Cybersecurity, iOS vulnerabilities, iPhone, malicious themes, Spyware, WebKit flaws, website security

Post navigation

Previous Post: Nutex Health Confirms Data Breach by Ransomware Group

Related Posts

Kimsuky APT Data Leak – GPKI Certificates, Rootkits and Cobalt Strike Personal Uncovered Kimsuky APT Data Leak – GPKI Certificates, Rootkits and Cobalt Strike Personal Uncovered Cyber Security News
Exploit Released for Splunk Secure Gateway Vulnerability Exploit Released for Splunk Secure Gateway Vulnerability Cyber Security News
AI Browsers Present New Security Risks with Prompt Injection AI Browsers Present New Security Risks with Prompt Injection Cyber Security News
Beware! Fake AI Video Generation Platforms Drop Stealer Malware on Your Computers Beware! Fake AI Video Generation Platforms Drop Stealer Malware on Your Computers Cyber Security News
OpenMatter Highlights Verification at Belgrade Blockchain OpenMatter Highlights Verification at Belgrade Blockchain Cyber Security News
NVIDIA and Lakera AI Propose Unified Framework for Agentic System Safety NVIDIA and Lakera AI Propose Unified Framework for Agentic System Safety Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Website Themes to Steal iPhone Crypto Data
  • Nutex Health Confirms Data Breach by Ransomware Group
  • METR Faces Security Breach, Loses $600,000 in AI Credits
  • Compromise of Popular npm Package Sparks Security Concerns
  • Exploitation of Critical JFrog Artifactory Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Website Themes to Steal iPhone Crypto Data
  • Nutex Health Confirms Data Breach by Ransomware Group
  • METR Faces Security Breach, Loses $600,000 in AI Credits
  • Compromise of Popular npm Package Sparks Security Concerns
  • Exploitation of Critical JFrog Artifactory Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark