13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
AI Summary
Security researchers have uncovered 13 malicious Packagist packages distributed under five vendor namespaces that target unpatched iOS devices through compromised Vietnamese movie and comic streaming sites. The packages inject JavaScript to conduct ad fraud and gambling redirects, while also deploying a WebKit-to-kernel exploit chain on iPhones to install spyware. The exploit chain leverages CVE-2025-31277 and CVE-2025-43529, ultimately achieving kernel-level access to steal sensitive data including keychain databases, Wi-Fi passwords, SMS, photos, and cryptocurrency wallet seeds from popular wallets like Trust Wallet and Phantom. The stolen data is encrypted with AES and exfiltrated to command and control domains, with exploitation progress beaconed to cloudfareintcdn[.]com.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 15 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | cloudfareintcdn[.]com | Details → |
| Domain | funnull-hosted | Details → |
| Package | vsmov/theme-dy | Details → |
| Package | vsmov/theme-rrdyw | Details → |
| Package | vsmov/theme-motchill | Details → |
| Package | vsmov/theme-vsmov | Details → |
| Package | vsphim/theme-heovl | Details → |
| Package | vsphim/theme-thempho | Details → |
| Package | haiau009/kkphim-legend | Details → |
| Package | haiau009/kkphim-motchill | Details → |
| Package | chilltvcms/theme-legend | Details → |
| Package | ophimcms/theme-dy | Details → |
| Package | ophimcms/theme-motchill | Details → |
| Package | ophimcms/theme-pcc | Details → |
| Package | ophimcms/theme-rrdyw | Details → |