Malicious Composer Packages on Packagist Deploy Spyware to Harvest Crypto Seeds from Unpatched iPhones
Cybersecurity analysts have uncovered a coordinated campaign involving 13 compromised Composer theme packages hosted on the popular PHP repository Packagist. The packages silently embed JavaScript into Vietnamese movie and comic streaming websites that rely on them, triggering the delivery of spyware designed to infiltrate iOS devices that have not applied the latest security updates. The ultimate goal of the malicious code is to extract cryptocurrency wallet seed phrases from vulnerable phones.
Packagist serves as the central distribution point for Composer, the dependency manager used by millions of PHP developers to incorporate reusable libraries into web applications. Because developers often trust the repository’s reputation and install packages with minimal review, malicious actors can exploit this trust chain by publishing seemingly benign themes that conceal harmful payloads. Supply‑chain attacks of this nature have risen in prominence as attackers seek to reach large user bases through trusted software ecosystems.
In the current case, each of the tainted theme packages modifies the HTML output of the streaming sites that adopt them, inserting obfuscated JavaScript code that runs in the visitor’s browser. The script first checks the visitor’s operating system and version; if it detects an iPhone running an iOS build that lacks recent patches, it proceeds to exploit a known vulnerability that allows remote code execution. Once the exploit succeeds, the malware gains the ability to read data stored on the device, including the seed phrases that protect cryptocurrency wallets.
The focus on seed phrases is significant because these 12‑ to 24‑word strings grant full control over digital assets without any need for additional authentication. By stealing the seeds, attackers can reconstruct the victim’s wallets on their own devices and transfer funds at will. The campaign appears to target users of Vietnamese streaming platforms, a market where mobile browsing on iPhones is common and where many users may delay software updates due to limited awareness of security risks.
Following the discovery, the researchers notified Packagist and the maintainers of the affected themes. The malicious packages were promptly removed from the repository, and advisories have been issued urging developers to audit their Composer dependencies and to verify the provenance of any third‑party libraries they integrate. Users are also being warned to apply the latest iOS updates, as the exploited vulnerability has been patched by Apple in recent releases.
Experts say the incident underscores the need for continuous monitoring of open‑source supply chains and for end‑users to keep their devices current. As the cryptocurrency ecosystem grows, attackers are increasingly targeting the weakest link—unpatched software and insecure development practices—to gain access to valuable digital assets. Ongoing collaboration between security researchers, repository maintainers, and the broader developer community will be essential to mitigate similar threats in the future.
Comments (0)
Be the first to comment.
Join the discussion