Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: php-supply-chain (1 article)Clear

Malicious Packagist themes attack unpatched iPhones to steal wallet seed phrases

Researchers found thirteen malicious packages on Packagist, the PHP Composer registry, posing as content-management themes that inject JavaScript into the sites that use them. On visitors' devices the script runs gambling and ad-fraud redirects, and on iPhones it loads a WebKit exploit chain that, against unpatched devices, installs spyware and steals cryptocurrency wallet seed phrases. The packages span several vendor names and extend a campaign first seen in March that abused similar theme packages and attacker-hosted infrastructure. It is a reminder that a compromised server-side dependency can become a delivery system for attacks against every visitor, including mobile users, not just the server it runs on.

Check
Audit PHP Composer and Packagist dependencies, especially themes, for untrusted or recently changed packages, remove suspicious ones, and make sure devices, including iPhones, are patched against known WebKit flaws.
Affected
Websites pulling the malicious Composer themes and their visitors; injected JavaScript redirects users and, on unpatched iPhones, chains WebKit exploits to install spyware and steal cryptocurrency wallet seed phrases from victims.
Fix
Vet and pin server-side dependencies, monitor sites for injected scripts and unexpected redirects, keep client devices patched, use content security policies to limit injected code, and treat theme packages as supply-chain risk.