Unpatched iPhones Targeted by 13 Malicious Packages in Crypto Theft Campaign
Cybersecurity researchers have uncovered 13 malicious Composer theme packages on Packagist that are being used to deliver sophisticated spyware to unpatched iPhones, with the latest version of the campaign specifically targeting cryptocurrency wallet seeds and recovery mnemonics.
The malicious packages are spread across five vendor namespaces — vsmov, vsphim, haiau009, chilltvcms, and ophimcms — and are designed to inject JavaScript into Vietnamese movie and comic streaming websites that use the affected themes. Once installed by a website operator, the compromised themes can silently expose visitors to malicious code.
The attack has two major components. The first redirects mobile visitors through advertising and gambling infrastructure. The second targets iPhone users with a WebKit-to-kernel exploit chain capable of escaping browser security boundaries and installing spyware.
The iOS attack chain exploits CVE-2025-31277 and CVE-2025-43529, two WebKit vulnerabilities that have already been patched by Apple. The campaign specifically targets older iOS versions, with researchers observing exploitation against devices running iOS 18.4 through 18.6.x.
Once the exploit chain succeeds, the spyware can access a broad range of sensitive information, including Keychain databases, Wi-Fi passwords, SMS messages, contacts, photos, browser cookies, call history, location information, and account databases. The collected information is encrypted before being transmitted to attacker-controlled infrastructure.
The campaign became more dangerous in August 2026, when researchers observed a redeployed version of the malware containing dedicated cryptocurrency-wallet theft functionality. The spyware searches the iOS Keychain for wallet information associated with Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX. This turns the operation from a conventional surveillance campaign into a direct financial-theft threat.
Apple has already addressed the vulnerabilities used in the campaign. Researchers report that the relevant WebKit flaws were patched in iOS 18.7.3 and iOS 26.2, while the kernel-escape component was addressed earlier in iOS 26.1. Users running vulnerable versions should therefore prioritize updating their devices.
The incident highlights a growing cybersecurity trend in which software supply-chain compromises are being transformed into drive-by attacks against end users. Instead of directly attacking an iPhone, threat actors compromise software installed by websites and use those trusted environments to deliver exploits to visitors — ultimately putting sensitive personal information and cryptocurrency assets at risk.
