Malicious Composer Packages Steal Crypto Wallet Seeds from Vulnerable iPhones
Malicious Composer packages targeting Vietnamese CMS platforms have been identified by Socket's Threat Research Team. These packages, spread across five vendor namespaces, inject JavaScript into streaming sites built on OphimCMS and KKPhim.
The payload runs two attacks simultaneously: gambling redirects and ad injection for every mobile visitor, as well as a full WebKit-to-kernel exploit chain targeting iPhones on iOS 18.4 through 18.6.x.
The attack requires nothing from the user, just a page load on an unpatched iPhone. The injected script drops a hidden iframe, detects the visitor's iOS version, and loads a version-specific exploit payload.
Socket's researcher Kush Pandya compares the structure to the DarkSword exploit kit. Once inside, the spyware takes everything: iOS Keychain databases, including crypto wallet seeds and mnemonics, Wi-Fi passwords, SMS messages, contacts, and photos.
The data is AES-encrypted and exfiltrated via HTTPS POST to rotating C2 domains; exploitation progress beaconed to cloudfareintcdn[.]com. Around August 12, 2026, the threat actors redeployed the full iOS chain with a new payload adding that targeted crypto-wallet seed stealer, moving the campaign from broad surveillance app into direct financial theft.
The fix for iPhone users is immediate; the risk for site operators runs deeper. If your iPhone runs anything below iOS 18.7.3, update now. Users on the iOS 26 line should be on 26.2 or later.