Researchers say a website-based attack chain tied to poisoned software packages may have exposed iPhone users on older iOS versions to spyware capable of reaching sensitive phone data, including material related to crypto wallets.
Socket, a cybersecurity platform, said it found 13 malicious themes on Packagist that were designed for OphimCMS and KKPhim, tools used by some Vietnamese streaming sites. The packages were installed by website operators rather than iPhone users, but once active they injected JavaScript into web pages that could identify a visitor’s iOS version and serve a Safari exploit to vulnerable devices.
How the campaign was delivered
According to Socket, the malicious themes appeared under five publishers: vsmov, vsphim, haiau009, chilltvcms, and ophimcms. After installation, infected sites could show injected ads or gambling redirects to mobile visitors. For iPhone users, the same pages could also trigger a more targeted path based on the device’s software version.
That detail matters because the attack did not depend on a fake wallet app being installed on the phone. Researchers said visiting an affected Safari page on an outdated iPhone could be enough to expose a user to the exploit chain if the required conditions were met.
Exploit chain reached beyond the browser
Socket said the campaign used two WebKit entry points. It identified CVE-2025-31277 for iOS 18.4 and 18.5, and CVE-2025-43529 for iOS 18.6. From there, later stages were described as escaping WebKit’s protected process and reaching the iOS kernel, which would allow access to data that a normal website should not be able to read.
The researchers found code covering iPhone XS through iPhone 16 models running iOS 18.4 through 18.6.x. The sample they analyzed did not support iOS 18.7 or iOS 26. Socket said the spyware could collect Keychain records, messages, contacts, photos, browser cookies, Wi-Fi passwords, location history, and account databases.
An August update to the malware also looked for wallet-related material associated with Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX.
Separate reports point to related tooling
The source article also notes a separate SlowMist report that examined different infrastructure identified as WYINCC. That sample likewise targeted Safari on iOS 18.4 through 18.6.2, but it focused on a different set of wallets: imToken, TokenPocket, and TronLink.
SlowMist said the payload it reviewed could search app files, read decrypted Keychain entries, and monitor keyboard input while a targeted wallet was open, although it did not execute those functions on a victim device during analysis. The article cautions against merging the wallet lists because Socket and SlowMist were examining different delivery systems, even though both were linked to the DarkSword exploit family.
Google’s Threat Intelligence Group has tracked DarkSword since November 2025 and found several variants supporting iOS 18.4 through 18.7, according to the report.
Patches are the main defense
Apple has released fixes for the exploit chain in later iOS versions, making software updates the primary protection. As of September 4, 2026, Apple listed iOS 26.6.1 as its current release, while iPhone XS, XS Max, and XR devices could receive iOS 18.7.10.
The article says users should install the newest update offered for their device and enable automatic downloads and installations. For devices running iOS 26.1 or later, Apple also offers Background Security Improvements under Privacy & Security, which can deliver some WebKit and system protections between full updates.
The report adds that suspicious redirects alone do not prove infection. If exposure is suspected, users should update immediately, review wallet connections and active sessions, and, if unauthorized transfers appear or a security review confirms compromise, create a new wallet on a clean device with a new recovery phrase before moving remaining assets.
Source: Coin Edition