Trusted Design

13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds

概要

Thirteen malicious Composer theme packages published on Packagist across five vendor namespaces inject JavaScript into Vietnamese movie and comic streaming sites. The injected code executes two operations: a mobile ad-fraud and gambling redirect chain, and on iPhones, a WebKit-to-kernel exploit chain installing spyware. The iOS chain weaponizes CVE-2025-31277 and CVE-2025-43529, targeting devices running iOS 18.4 through 18.6.x on iPhone XS through iPhone 16. The exploit chain progresses from WebKit renderer through GPU process to kernel escape via AppleM2ScalerCSCDriver, ultimately deploying spyware that exfiltrates keychain databases, cryptocurrency wallet seeds from seven wallet applications, Wi-Fi passwords, SMS, photos, contacts, and location data. Infrastructure resolves to FUNNULL, a sanctioned provider operated by Chinese national Liu Lizhi. The theme operators are Vietnamese-based, publishing trojanized forks of OphimCMS and KKPhim projects, affecting site operators who unknowingly serve malicious...

Created: 2026-09-01

Indicators

Indicatorsは見つかっていない。

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

事実ベースの脅威アクターは見つかりませんでした。

このPulseに関連する脅威アクター (推論ベース)

推論ベースの脅威アクターは見つかりませんでした。

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る