Malicious Packagist themes attack unpatched iPhones to steal wallet seed phrases
Researchers found thirteen malicious packages on Packagist, the PHP Composer registry, posing as content-management themes that inject JavaScript into the sites that use them. On visitors' devices the script runs gambling and ad-fraud redirects, and on iPhones it loads a WebKit exploit chain that, against unpatched devices, installs spyware and steals cryptocurrency wallet seed phrases. The packages span several vendor names and extend a campaign first seen in March that abused similar theme packages and attacker-hosted infrastructure. It is a reminder that a compromised server-side dependency can become a delivery system for attacks against every visitor, including mobile users, not just the server it runs on.
- Check
- Audit PHP Composer and Packagist dependencies, especially themes, for untrusted or recently changed packages, remove suspicious ones, and make sure devices, including iPhones, are patched against known WebKit flaws.
- Affected
- Websites pulling the malicious Composer themes and their visitors; injected JavaScript redirects users and, on unpatched iPhones, chains WebKit exploits to install spyware and steal cryptocurrency wallet seed phrases from victims.
- Fix
- Vet and pin server-side dependencies, monitor sites for injected scripts and unexpected redirects, keep client devices patched, use content security policies to limit injected code, and treat theme packages as supply-chain risk.