Back to News
Cybersecurity

Malicious Packagist Packages Exploit Unpatched iPhones to Harvest Crypto Data

Cybersecurity experts uncover a series of malicious packages targeting unpatched iPhones, posing significant risks to crypto wallet security.

Recent findings from cybersecurity researchers reveal the discovery of 13 malicious Composer theme packages hosted on Packagist. These packages are engineered to inject harmful JavaScript into streaming sites for Vietnamese movies and comics, subsequently deploying spyware that specifically targets unpatched iOS devices. The injected code performs two primary operations against unsuspecting site visitors: mobile ad fraud and redirects to gambling sites, which could compromise user data and financial information.

For businesses, especially those in the technology and entertainment sectors, this situation underscores the critical need for robust cybersecurity measures. Companies must ensure that their platforms are not only free from such vulnerabilities but also regularly updated to mitigate the risks associated with unpatched software. This incident highlights the importance of vetting third-party packages and libraries, as malicious code can easily infiltrate legitimate platforms, putting sensitive user data, particularly cryptocurrency wallet seeds, at risk. As the threat landscape continues to evolve, organizations must prioritize cybersecurity protocols and user education to safeguard against these increasingly sophisticated attacks.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html)*