NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
LatestDaily BriefMarkets
NewsLayer PulseLIVE₿BTC$77,686+0.09%ΞETH$2,401-0.81%◎SOL$100.67+0.46%✕XRP$1.37+1.26%ÐDOGE$0.0829+1.20%₳ADA$0.2065+4.02%Total Cap$2.74T-0.10%24H Vol$359.6BLayer Index48 Neutral
BreakingEU weighs new Russia sanctions after Germany blames Moscow for drone attackil y a 8 heures
Markets
HomeCrypto

Crypto

13 Malicious Packages Turn iPhones Into Crypto Theft Targets

Visiting a Vietnamese streaming site — without clicking a link or downloading a file — can silently drain a crypto wallet. Socket’s Threat Research Team identified 13 malicious Composer/Packagist theme packages, spread across five…

Gadget Review

Publisher

Sep 2, 2026 at 3:20 PM UTC · 3 min de lecture

13 Malicious Packages Turn iPhones Into Crypto Theft Targets
Image via Gadget Review

Key Signal

13 malicious theme packages identified

Last Updated

il y a 14 heures

Traduction…

Visiting a Vietnamese streaming site — without clicking a link or downloading a file — can silently drain a crypto wallet. Socket’s Threat Research Team identified 13 malicious Composer/Packagist theme packages, spread across five vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms), injecting JavaScript into streaming sites built on OphimCMS and KKPhim. The payload runs two attacks simultaneously: gambling redirects and ad injection for every mobile visitor, and a full WebKit-to-kernel exploit chain targeting iPhones on iOS 18.4 through 18.6.x.

How a Movie Site Empties Your Wallet

The attack requires nothing from you — just a page load on an unpatched iPhone.

Buried in legitimate-looking theme code, the injected script drops a hidden iframe, detects the visitor’s iOS version, and loads a version-specific exploit payload. Think of it like a burglar who checks the lock model before choosing the right pick. The chain weaponizes two public WebKit vulnerabilities — CVE-2025-31277 (patched in iOS 18.6) and CVE-2025-43529 (patched in iOS 18.7.3 and 26.2) — to escape Safari’s sandbox, pivot through the GPU process, and reach the kernel via the AppleM2ScalerCSCDriver IOKit user client. The result is full kernel read/write access. Socket’s researcher Kush Pandya compares the structure to the DarkSword exploit kit.

Article Intelligence

Topics

crypto

Sponsored

Ad
House — Advertise on NewsLayer
NewsLayerLearn more

NewsLayer Premium

Unlock deeper intelligence.

Ad-free reading, exclusive research, and real-time onchain insights.

Go Premium
NewsLayer.com

The front page of the onchain economy. Crypto, Web3 and regulation intelligence — live prices, original research and policy tracking in one layer.

Follow on XTelegram

News

  • Latest News
  • The Daily Brief
  • Crypto
  • DeFi
  • Policy
  • Web3
  • Blockchain
  • Explainers

Markets

  • Market News
  • Layer Index
  • Live Charts
  • DeFi Protocols
  • Regulation Tracker
  • Regulation Radar

Company

  • About NewsLayer
  • Advertise
  • PR Publication
  • Become an Author
  • Our Authors
  • Create Account
  • Sign in

Resources

  • Research
  • NewsLayer Originals
  • My Feed
  • Search
  • AI Sector
  • Quantum Sector

NewsLayer Premium

Read the full layer.

Unlock premium intelligence, original research and an ad-free reading experience.

  • Premium Intelligence briefings
  • Ad-free reading experience
  • Members-only research & data
Go Premium

© 2026 NewsLayer.com — The front page of the onchain economy

Privacy Policy·Terms of Service
NewsLayer

Get the signal, not the noise.

Markets, regulation and onchain intelligence in a 5-minute morning read — plus breaking alerts and Layer Index flips as they happen.

The Daily Brief

Breaking alerts

Index flips

Free · No spam · Unsubscribe anytime