Malicious iPhone Website Themes Steal Crypto Wallet Seeds
Key Takeaways Malicious website themes are being leveraged to deliver spyware and facilitate cryptocurrency theft from iPhone users. The attack primarily targets visitors to Vietnamese movie and...
Key Takeaways
- Malicious website themes are being leveraged to deliver spyware and facilitate cryptocurrency theft from iPhone users.
- The attack primarily targets visitors to Vietnamese movie and comic streaming websites.
- Threat actors use compromised Composer themes to inject harmful JavaScript, which then exploits known WebKit vulnerabilities (CVE-2025-31277 and CVE-2025-43529) on older iOS versions.
- The spyware exfiltrates sensitive data, including crypto wallet seed phrases, from affected iPhones.
- Devices running iOS 18.7.3 (iOS 18 line) or iOS 26.2 and later are not vulnerable to the currently identified exploit chain.
Hackers Exploit Website Themes to Target iPhones
Cybercriminals are deploying sophisticated tactics, embedding malicious code within popular website themes to compromise iPhones and steal cryptocurrency. This campaign specifically targets users visiting Vietnamese movie and comic streaming platforms, turning seemingly innocuous browsing into a high-stakes security incident.
Table Of Content
The attackers inject their harmful scripts into website themes distributed via Composer, a widely used dependency manager for PHP. Once a website operator integrates one of these compromised themes, the malicious code is automatically served to every visitor, silently initiating the attack chain.
While some mobile users might be redirected to gambling sites, a more insidious threat awaits selected iPhone visitors. The malicious script, delivered through what appears to be a legitimate streaming service, can trick users into believing they are interacting with a normal, trusted platform.
Uncovering the Malicious Infrastructure
Socket.dev said in a report, which was also shared with Cyber Security News (CSN), that their investigation uncovered 13 malicious theme packages distributed across five distinct namespaces. This discovery significantly expands on previous research, highlighting how a compromised front-end theme can serve as an effective and stealthy conduit for attacks against a website’s user base.
The campaign poses a dual threat: website operators unknowingly become vectors for attack, while their visitors face potential exposure of private device data and, critically, cryptocurrency wallet recovery information. This scenario mirrors past supply chain compromises, such as the npm package compromise incidents, where seemingly legitimate software updates become a vector for attack.
Sophisticated Attack Chain and Exploitation
The malicious themes contain embedded JavaScript loaders. These loaders are designed to evade detection by checking the visitor’s device and referral source, bypassing desktop browsers, automated scanners, and direct navigations. This selective targeting helps the attackers remain undetected.
For mobile visitors, the attack branches. Some are subjected to advertising injections and redirected through gambling sites. However, specific iPhone users who meet the campaign’s criteria face a more severe threat. A separate loader retrieves additional malicious code from attacker-controlled infrastructure. A hidden page then identifies the iPhone’s iOS version to deploy a tailored exploit.
The research indicates the web attack leverages two known WebKit vulnerabilities: CVE-2025-31277 and CVE-2025-43529. These flaws allow the attackers to move beyond the browser and gain deeper access to the device. While Apple has addressed the kernel escape vulnerability mentioned by researchers, and the targeted WebKit entry points are publicly known and patched, this campaign highlights the critical importance of timely software updates, as seen in previous Apple WebKit zero-day flaws.
The attack targets iPhones from the XS generation up to the iPhone 16 family that are running older iOS versions. The report specifies that devices updated to iOS 18.7.3 (on the iOS 18 line) or iOS 26.2 and later are not susceptible to the identified stages of this operation, indicating the attackers rely on users delaying updates rather than exploiting current protections.
Spyware Exfiltrates Sensitive Data and Crypto Wallet Seeds
Upon successful compromise, the spyware aggressively collects a wide array of highly personal information. This includes keychain databases, Wi-Fi passwords, text messages, contact lists, photos, browser cookies, call history, location data, and various account details. The stolen data is then encrypted and transmitted to a dynamic network of command-and-control (C2) servers.
A redeployed version of the malware, observed in August, introduced a dedicated cryptocurrency wallet theft capability. This enhanced functionality specifically targets the iPhone keychain to extract seed phrases and mnemonic information from cryptocurrency wallets. These recovery phrases grant attackers full control over a victim’s digital assets, making this incident far more financially devastating than a typical data breach.
The attackers have continuously refined their tactics, refreshing filenames and staging components while old files remain accessible, complicating detection and takedown efforts. This behavior is consistent with other package ecosystem threats, where seemingly benign code can surreptitiously collect sensitive information post-installation.
What You Should Do
- For Website Operators:
- Immediately remove any untrusted or suspicious themes from your content management systems.
- Thoroughly review all front-end scripts for unauthorized modifications or injected code.
- Rotate all credentials handled on the affected host.
- Inspect network activity for any of the indicators of compromise (IoCs) listed below.
- Developers should pin and meticulously review Composer dependencies, including themes and assets, as client-side code executes with the same impact as server-side code.
- For iPhone Users:
- Prioritize and apply all available iOS updates immediately. Devices running iOS 18.7.3 (iOS 18 line) or iOS 26.2 and later are currently protected from this specific exploit chain.
- Be cautious of unsolicited redirects, especially to gambling or unfamiliar sites, when browsing.
- Consider using a reputable ad blocker and script blocker for enhanced browser security.
- For Security Teams:
- Block all listed network indicators of compromise (IoCs) at your perimeter.
- Actively monitor for suspicious page loaders, hidden iframes, and unusual browser requests within your network traffic.
- Ensure all managed iPhones are updated to the latest available iOS versions to mitigate known vulnerabilities.
- Educate users on the risks of <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/95f0d62b-1a54-49de-b7ff-e95fddbc436acc24a654092f5205b2c5bd3208b126b2c2754ac63e7aea22298/Hackers-Use-Malicious-Website-Themes-to-Steal-Crypto-Wallet-Seeds-From-iPhones.pdf?AWSAccessKeyId=ASIA2F3EMEYE7YOAS7JZ&Signature=86PoZVH4DDuJcxM67FMMsmbKpLU%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEN%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwE
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.