Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious Packages Target iPhones for Crypto Theft

Malicious Packages Target iPhones for Crypto Theft

Posted on September 1, 2026 By CWS

Cybersecurity experts have recently uncovered a series of 13 malicious packages on Packagist, specifically designed to inject harmful JavaScript into Vietnamese movie and comic streaming platforms. These packages target unpatched iPhones, deploying spyware to extract sensitive information, including cryptocurrency wallet seeds.

How the Malicious Packages Operate

The threat is executed by injecting code that performs two main operations: redirecting mobile traffic for ad-fraud and gambling, and exploiting iPhones through a WebKit-to-kernel chain to install spyware. This was highlighted by security researcher Kush Pandya from Socket. The campaign traces back to March 2026, initially involving six Packagist packages masquerading as OphimCMS themes, which rerouted traffic and exfiltrated data.

The affected packages span across multiple namespaces including vsmov, vsphim, haiau009, chilltvcms, and ophimcms. These trojanized themes inject scripts that lead to spyware installations, ultimately resulting in the theft of cryptocurrency wallet information.

Details of the iOS Exploit Chain

The exploitation method involves inserting a hidden iframe to identify the iOS version and load a corresponding exploit. This attack leverages two known WebKit vulnerabilities, CVE-2025-31277 and CVE-2025-43529, akin to the techniques used in the DarkSword exploit kit. Apple has since patched these vulnerabilities in later iOS versions.

Once the attack is successful, the spyware gains access to the device’s kernel, allowing it to extract and encrypt sensitive data such as keychain databases, SMS logs, and browser cookies, which are then uploaded to remote servers.

Implications and Preventative Measures

The campaign saw a resurgence on August 12, 2026, with a new payload specifically targeting iOS devices with versions between 18.4 and 18.6.x. This payload seeks out cryptocurrency wallet data from several wallet apps, widening the impact from data theft to direct financial losses.

Despite the malicious nature of these packages, some additional theme packages published by the same vendors were found without active payloads but could be activated through specific site configurations. The campaign is suspected to be run by a Vietnamese group, with infrastructure linked to the sanctioned entity Funnull.

Website operators using sensitive themes like OphimCMS or KKPhim are urged to verify their installations, remove any suspicious packages, and conduct thorough security audits to mitigate potential threats. Regular updates and a vigilant approach to cybersecurity can help protect against such vulnerabilities.

The Hacker News Tags:crypto theft, Cybersecurity, iOS exploit, iPhone, JavaScript injection, malicious packages, OphimCMS themes, Packagist, Spyware, WebKit vulnerabilities

Post navigation

Previous Post: Five Hackers Admit to ATM Malware Attacks in Kansas
Next Post: WatchGuard Addresses Critical Security Flaws in Fireware OS

Related Posts

SkillCloak Evades AI Scanners with New Techniques SkillCloak Evades AI Scanners with New Techniques The Hacker News
Federal Push for Post-Quantum Security by 2030 Federal Push for Post-Quantum Security by 2030 The Hacker News
CL0P-Linked Hackers Breach Dozens of Organizations Through Oracle Software Flaw CL0P-Linked Hackers Breach Dozens of Organizations Through Oracle Software Flaw The Hacker News
Hidden Logic Bombs in Malware-Laced NuGet Packages Set to Detonate Years After Installation Hidden Logic Bombs in Malware-Laced NuGet Packages Set to Detonate Years After Installation The Hacker News
F5 Breached, Linux Rootkits, Pixnapping Attack, EtherHiding & More F5 Breached, Linux Rootkits, Pixnapping Attack, EtherHiding & More The Hacker News
Malicious Notepad++ Plugin Exploits in UAC-0099 Campaign Malicious Notepad++ Plugin Exploits in UAC-0099 Campaign The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Exploits Target Langflow and Ruby on Rails Systems
  • WatchGuard Addresses Critical Security Flaws in Fireware OS
  • Malicious Packages Target iPhones for Crypto Theft
  • Five Hackers Admit to ATM Malware Attacks in Kansas
  • Venezuelan Nationals Admit to ATM Jackpotting in US

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Exploits Target Langflow and Ruby on Rails Systems
  • WatchGuard Addresses Critical Security Flaws in Fireware OS
  • Malicious Packages Target iPhones for Crypto Theft
  • Five Hackers Admit to ATM Malware Attacks in Kansas
  • Venezuelan Nationals Admit to ATM Jackpotting in US

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark