13 Malicious Composer Themes Exploit WebKit Vulnerabilities to Steal iOS Crypto Wallets
13 malicious Composer theme packages on Packagist exploit WebKit vulnerabilities CVE-2025-31277 and CVE-2025-43529 to deploy spyware on unpatched iOS devices, stealing crypto wallet seeds and sensitive data through a WebKit-to-kernel exploit chain. The attack targets iOS 18.4-18.6.x via compromised Vietnamese streaming sites, leveraging Funnull's infrastructure for data exfiltration and financial theft.
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices.
"The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect
*** END OF TRANSMISSION ***