[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:13-malicious-packagist-packages-target-unpatched-iphones-to-steal-crypto-wallet--mtj3lmo7":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":17,"article_ids":18,"ioc_summary":20,"source_urls":21,"status":23,"expires_at":24,"created_at":25,"updated_at":26,"articles":27},"60ea571f-2eb3-4913-a65f-c4b1f1d25054","13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds","13-malicious-packagist-packages-target-unpatched-iphones-to-steal-crypto-wallet--mtj3lmo7","Thirteen malicious Composer packages on Packagist have been injected into Vietnamese streaming sites to deploy iOS spyware targeting unpatched iPhones. The campaign, active since March 2026, exploits WebKit vulnerabilities to steal cryptocurrency wallet seeds and execute ad-fraud redirects. Any developer using these packages or users accessing compromised streaming sites face wallet compromise and credential theft.","critical","advisory",[],[13,14,15,16],"Composer","OphimCMS","iOS","Funnull","Identify and quarantine any use of malicious Packagist packages in your supply chain. Cross-reference developer environments and production deployments against the IOC list. Scan logs for Composer installations from Packagist between March 2026 and present. Brief finance and crypto-custodian teams on wallet seed exposure risk.",[19],"30f4a021-57c9-4c4c-ac6e-3976d955f277",null,[22],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002F13-malicious-packagist-packages-target.html","active","2026-09-03T20:06:39.591+00:00","2026-09-01T20:06:43.285952+00:00","2026-09-01T20:06:47.413333+00:00",[28],{"id":19,"title":6,"url":22}]