Malicious Packagist Packages Found Targeting Unpatched iPhones to Steal Crypto Wallet Data
Cybersecurity researchers have uncovered 13 malicious Composer theme packages hosted on Packagist, the main repository for PHP software packages. These packages are designed to inject malicious JavaScript into Vietnamese movie and comic streaming websites that use them, turning legitimate-looking sites into delivery mechanisms for further attacks.
Once embedded, the injected code runs two coordinated operations against site visitors: one focused on mobile ad-fraud and gambling redirects, and another that attempts to deploy spyware on unpatched iOS devices. The ultimate goal of the iOS-targeting component appears to be stealing cryptocurrency wallet seed phrases, giving attackers a path to drain victims' digital assets. Because the compromise happens through the software supply chain, developers who unknowingly include these packages in their projects can expose their own users to risk without any direct wrongdoing on their part.
This incident is a reminder that open-source package repositories, while essential to modern software development, are increasingly being used as a vector for distributing malware. Businesses that rely on third-party code — which is nearly all businesses — need to treat their software supply chain as part of their attack surface, not just their own infrastructure.