13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. "The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect
- 1. 13 malicious Composer theme packages on Packagist inject spyware into Vietnamese movie and comic streaming sites, targeting unpatched iOS devices.
- 2. The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect chain, and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware.
- 3. The malware queries the password store for wallet material from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX, extending beyond device data collection to direct financial theft.
Article analysis
Skim this article about "13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds": 3 key takeaways and more.
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
skim AI Analysis | The Hacker News
The Hacker News on 13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds: skim's analysis surfaces 3 key takeaways. 13 malicious Composer packages on Packagist inject spyware into streaming sites, targeting unpatched iPhones to steal crypto wallet seeds. Read the takeaways in seconds, then decide whether the full article is worth your time.
Category: Tech. News article analyzed by skim.
Summary
13 malicious Composer packages on Packagist inject spyware into streaming sites, targeting unpatched iPhones to steal crypto wallet seeds. The attack exploits WebKit vulnerabilities to gain kernel privileges, exfiltrating sensitive data and financial information. The campaign, potentially Vietnamese-operated, also involves ad-fraud and gambling redirects.
Key Takeaways
- 13 malicious Composer theme packages on Packagist inject spyware into Vietnamese movie and comic streaming sites, targeting unpatched iOS devices.
- The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect chain, and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware.
- The malware queries the password store for wallet material from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX, extending beyond device data collection to direct financial theft.
Statement Breakdown
- Claimed Facts: 70% of statements the article presents as facts
- Opinions: 20% of statements classified as editorial or subjective
- Claims: 10% of statements surfaced for additional reader evaluation
Credibility & Bias Reasoning
Credibility assessment: The article presents detailed technical information about a cybersecurity threat, citing specific vulnerabilities and exploit chains. It attributes findings to a security research company, enhancing its credibility. The information is presented factually, with clear explanations of the attack's methodology and impact.
Bias assessment: Technical Security Reporting. The article focuses on reporting a technical cybersecurity threat with a neutral, informative tone. It avoids emotional language or partisan framing, concentrating on the facts of the attack and its implications for users and developers.
Note: This article details a sophisticated cybersecurity threat. While technically sound, users should verify findings with official security advisories and exercise caution with software from untrusted sources.
Credibility flag: Technical, Verify
Claimed Facts (8)
- This is a factual statement about the discovery of malicious packages.
- This provides a specific list of identified malicious packages.
- This describes a technical mechanism used in the attack.
- This cites specific CVEs and their patch status, presenting factual technical details.
- This details the technical progression of the exploit chain.
- This states a fact about Apple's security updates.
- This provides a specific timeline and target for a redeployed campaign.
- This presents a factual observation about the current state of other packages.
Opinions (5)
- This is a direct quote from a security researcher, representing their assessment and interpretation of the code's function.
- This is a quote from a researcher explaining the perceived outcome of the exploit, which involves interpretation of the payload's actions.
- This is a statement about the observed behavior of the malware, which is an interpretation of network activity.
- This is a hypothetical scenario presented by Socket, outlining the potential impact on a user.
- This is an assessment of the role and impact on website operators, framed as an opinion.
Claims (2)
- The attribution to a 'Vietnamese-operated group' is presented as a belief based on limited evidence (commit metadata timestamps), making it a less substantiated claim.
- While Funnull's sanctioning is a factual event, linking it directly to this specific campaign without more explicit evidence of Funnull's direct involvement in facilitating *this* particular attack could be considered a speculative connection.
Key Sources
- The Hacker News — Media
- Kush Pandya — Security Researcher, Socket
- Socket — Application Security Company
This analysis was generated by skim (skim.plus), an AI-powered content analysis platform by Credible AI. Scores and classifications represent the platform's AI-generated assessment and should be considered alongside other sources.
skim analyzes recent The Hacker News coverage for what holds up, what reads as opinion, and what may not be fully supported. Last updated 1st September 2026.