Malicious Packagist Packages Exploit Unpatched iOS WebKit to Steal Crypto Seeds
Attackers published 13 malicious Composer packages on Packagist — a trusted PHP dependency registry — to inject JavaScript into Vietnamese streaming sites, demonstrating how supply chain compromise can weaponize developer ecosystems against end users. The injected scripts exploited unpatched WebKit vulnerabilities on iOS devices, enabling theft of cryptocurrency wallet seed phrases, which permanently compromises a victim's funds with no recovery path. This campaign highlights the dual risk of unvetted open-source dependencies and delayed mobile OS patching, where either failure alone creates an exploitable gap. The combination of supply chain infiltration and client-side exploitation underscores that defending users requires both securing the software pipeline and maintaining up-to-date device firmware.
Tactical Insight
Immediate actions
- Audit all Composer/Packagist dependencies in your projects using tools like `composer audit` or Sonatype Nexus to identify and remove the 13 known malicious packages.
- Apply the latest iOS and WebKit security updates immediately across all managed and BYOD devices to close the exploited vulnerabilities.
- Implement Subresource Integrity (SRI) hashes on all third-party JavaScript inclusions to detect unauthorized script injection.
Long-term improvements
- Establish a formal Software Composition Analysis (SCA) process that automatically scans all open-source dependencies before merging into production pipelines.
- Enforce a Mobile Device Management (MDM) policy that mandates minimum OS patch levels and blocks non-compliant devices from accessing corporate or sensitive resources.
- Maintain a vetted, internal package mirror or allowlist of approved Packagist packages to prevent developers from pulling unreviewed dependencies.
Detection measures
- Deploy Content Security Policy (CSP) headers on all web properties to detect and block unauthorized JavaScript execution from unexpected sources.
- Monitor dependency manifests (`composer.lock`) for unexpected changes or newly added packages as part of your CI/CD pipeline security checks.
- Enable mobile threat detection tooling to alert on spyware behaviors such as unauthorized access to clipboard or wallet application data on iOS devices.