hacker-news · Crawled Sep 1, 2026

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

15 IoCs 2 CVEs
Read original article ↗

AI Summary

Security researchers have uncovered 13 malicious Packagist packages distributed under five vendor namespaces that target unpatched iOS devices through compromised Vietnamese movie and comic streaming sites. The packages inject JavaScript to conduct ad fraud and gambling redirects, while also deploying a WebKit-to-kernel exploit chain on iPhones to install spyware. The exploit chain leverages CVE-2025-31277 and CVE-2025-43529, ultimately achieving kernel-level access to steal sensitive data including keychain databases, Wi-Fi passwords, SMS, photos, and cryptocurrency wallet seeds from popular wallets like Trust Wallet and Phantom. The stolen data is encrypted with AES and exfiltrated to command and control domains, with exploitation progress beaconed to cloudfareintcdn[.]com.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 15 extracted

Type Value Detail
Domain cloudfareintcdn[.]com Details →
Domain funnull-hosted Details →
Package vsmov/theme-dy Details →
Package vsmov/theme-rrdyw Details →
Package vsmov/theme-motchill Details →
Package vsmov/theme-vsmov Details →
Package vsphim/theme-heovl Details →
Package vsphim/theme-thempho Details →
Package haiau009/kkphim-legend Details →
Package haiau009/kkphim-motchill Details →
Package chilltvcms/theme-legend Details →
Package ophimcms/theme-dy Details →
Package ophimcms/theme-motchill Details →
Package ophimcms/theme-pcc Details →
Package ophimcms/theme-rrdyw Details →

MITRE ATT&CK TTPs 6 techniques