Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageVulnerabilities Desk
Vulnerabilities

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

Thirteen malicious Composer packages on Packagist inject JavaScript to deliver iOS spyware—a multi-stage supply-chain attack that underscores the need for dependency provenance checks in PHP ecosystems.

Summary written by editorial AI · Source link below

Filed by THN (Feedburner)1 min readRead at source ↗

Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices.

"The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect

Editorial Analysis

Why it matters

PHP/Composer supply-chain attacks remain undermonitored compared to npm or PyPI; enterprises using Packagist dependencies should treat this as a reminder to extend supply-chain security controls to all package ecosystems.

What to do

Scan Composer lock files for the identified malicious packages and implement automated dependency provenance verification in PHP CI/CD pipelines.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at THN (Feedburner)

External link — opens at THN (Feedburner) in a new tab.

§
Continue with

More from the Vulnerabilities Desk