Malware

Malicious Composer themes deliver spyware to unpatched iOS devices

iPhone 13 Pro with apple logo loading and installing operating system ios 15.5 on the screen close up, new ios 2022 on apple devices sub v. ios 15 for updates

The Hacker News reports that a campaign has been discovered involving 13 malicious Composer theme packages on Packagist, designed to inject JavaScript into Vietnamese movie and comic streaming sites. These packages aim to deploy spyware targeting unpatched iOS devices, according to Socket researchers.

The malicious code performs two main functions: a mobile ad-fraud and gambling-redirect chain, and a WebKit-to-kernel exploit chain on iPhones that installs spyware. This campaign, first documented in March 2026, leverages packages posing as OphimCMS themes. The injected JavaScript targets visitors, leading them to gambling and adult content sites. The iOS exploit chain weaponizes WebKit vulnerabilities CVE-2025-31277 and CVE-2025-43529, analogous to the DarkSword exploit kit. The payload escalates privileges to the kernel, enabling the theft of sensitive data including keychain databases, Wi-Fi passwords, SMS messages, contacts, photos, browser cookies, and cryptocurrency wallet seeds.

The threat actors, believed to be a Vietnamese-operated group, redeployed the iOS chain around August 12, 2026, specifically targeting iOS versions 18.4 through 18.6.x with a payload that includes a cryptocurrency wallet stealer. The infrastructure used for the iOS exploits is linked to Funnull, an entity previously sanctioned by the U.S. for facilitating scams. Site operators using OphimCMS or KKPhim are advised to check for and remove any of the identified malicious packages, rotate credentials, and audit their scripts.

Source: The Hacker News

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds