FomoPeek and DarkSword Malware Exposes Crypto Wallet Security Risks
Crypto wallet security has been compromised by malicious code in FomoPeek and DarkSword, according to SlowMist.
FomoPeek, a cryptocurrency tracking tool available on the App Store, was found to contain two malicious modules: apptrace and libapptracecore. These modules were introduced in version 1.1 of the application, released on September 9. The code allowed for eight different exploitation methods, including bypassing the Apple application sandbox and stealing information from the Keychain.
The private keys, recovery phrases, logins, passwords, and data from other apps were available for extraction by hackers. Researchers also uncovered hidden command-and-control infrastructure that targeted 19 wallet and note-taking apps, as well as Apple Notes. FomoPeek's version history was used to trace the malicious modules.
DarkSword, on the other hand, is a browser exploit framework first identified by Google in March after monitoring its activities since November 2025. It made use of six vulnerabilities to attack iPhones running iOS 18.4 through 18.7 and deployed malicious code via infected websites. The campaigns involved users from Saudi Arabia, Turkey, Malaysia, and Ukraine.