13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Thirteen malicious Composer packages on Packagist inject JavaScript to deliver iOS spyware—a multi-stage supply-chain attack that underscores the need for dependency provenance checks in PHP ecosystems.
Summary written by editorial AI · Source link below
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices.
"The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect
Editorial Analysis
PHP/Composer supply-chain attacks remain undermonitored compared to npm or PyPI; enterprises using Packagist dependencies should treat this as a reminder to extend supply-chain security controls to all package ecosystems.
Scan Composer lock files for the identified malicious packages and implement automated dependency provenance verification in PHP CI/CD pipelines.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Vulnerabilities Desk
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores2d
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code2d
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities3d
- Government Rails Site Hit Hours After CVE Patch3d
- Critical Citrix NetScaler auth bypass now leveraged in attacks3d