Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Vulnerability in Popular npm Package Exposes Users to Supply Chain Attacks
September 1, 2026
Malicious iPhone Website Themes Steal Crypto Wallet Seeds
September 1, 2026
Cisco Routers Vulnerable to State-Sponsored Attacks, Critical Infrastructure at Risk
September 1, 2026
Home/Threats/Malicious iPhone Website Themes Steal Crypto Wallet Seeds
Threats

Malicious iPhone Website Themes Steal Crypto Wallet Seeds

Key Takeaways Malicious website themes are being leveraged to deliver spyware and facilitate cryptocurrency theft from iPhone users. The attack primarily targets visitors to Vietnamese movie and...

Sarah simpson
Sarah simpson
September 1, 2026 4 Min Read
3 0

Key Takeaways

  • Malicious website themes are being leveraged to deliver spyware and facilitate cryptocurrency theft from iPhone users.
  • The attack primarily targets visitors to Vietnamese movie and comic streaming websites.
  • Threat actors use compromised Composer themes to inject harmful JavaScript, which then exploits known WebKit vulnerabilities (CVE-2025-31277 and CVE-2025-43529) on older iOS versions.
  • The spyware exfiltrates sensitive data, including crypto wallet seed phrases, from affected iPhones.
  • Devices running iOS 18.7.3 (iOS 18 line) or iOS 26.2 and later are not vulnerable to the currently identified exploit chain.

Hackers Exploit Website Themes to Target iPhones

Cybercriminals are deploying sophisticated tactics, embedding malicious code within popular website themes to compromise iPhones and steal cryptocurrency. This campaign specifically targets users visiting Vietnamese movie and comic streaming platforms, turning seemingly innocuous browsing into a high-stakes security incident.

Table Of Content

  • Key Takeaways
  • Hackers Exploit Website Themes to Target iPhones
  • Uncovering the Malicious Infrastructure
  • Sophisticated Attack Chain and Exploitation
  • Spyware Exfiltrates Sensitive Data and Crypto Wallet Seeds
  • What You Should Do

The attackers inject their harmful scripts into website themes distributed via Composer, a widely used dependency manager for PHP. Once a website operator integrates one of these compromised themes, the malicious code is automatically served to every visitor, silently initiating the attack chain.

While some mobile users might be redirected to gambling sites, a more insidious threat awaits selected iPhone visitors. The malicious script, delivered through what appears to be a legitimate streaming service, can trick users into believing they are interacting with a normal, trusted platform.

Uncovering the Malicious Infrastructure

Socket.dev said in a report, which was also shared with Cyber Security News (CSN), that their investigation uncovered 13 malicious theme packages distributed across five distinct namespaces. This discovery significantly expands on previous research, highlighting how a compromised front-end theme can serve as an effective and stealthy conduit for attacks against a website’s user base.

The campaign poses a dual threat: website operators unknowingly become vectors for attack, while their visitors face potential exposure of private device data and, critically, cryptocurrency wallet recovery information. This scenario mirrors past supply chain compromises, such as the npm package compromise incidents, where seemingly legitimate software updates become a vector for attack.

Sophisticated Attack Chain and Exploitation

The malicious themes contain embedded JavaScript loaders. These loaders are designed to evade detection by checking the visitor’s device and referral source, bypassing desktop browsers, automated scanners, and direct navigations. This selective targeting helps the attackers remain undetected.

For mobile visitors, the attack branches. Some are subjected to advertising injections and redirected through gambling sites. However, specific iPhone users who meet the campaign’s criteria face a more severe threat. A separate loader retrieves additional malicious code from attacker-controlled infrastructure. A hidden page then identifies the iPhone’s iOS version to deploy a tailored exploit.

The research indicates the web attack leverages two known WebKit vulnerabilities: CVE-2025-31277 and CVE-2025-43529. These flaws allow the attackers to move beyond the browser and gain deeper access to the device. While Apple has addressed the kernel escape vulnerability mentioned by researchers, and the targeted WebKit entry points are publicly known and patched, this campaign highlights the critical importance of timely software updates, as seen in previous Apple WebKit zero-day flaws.

The attack targets iPhones from the XS generation up to the iPhone 16 family that are running older iOS versions. The report specifies that devices updated to iOS 18.7.3 (on the iOS 18 line) or iOS 26.2 and later are not susceptible to the identified stages of this operation, indicating the attackers rely on users delaying updates rather than exploiting current protections.

Spyware Exfiltrates Sensitive Data and Crypto Wallet Seeds

Upon successful compromise, the spyware aggressively collects a wide array of highly personal information. This includes keychain databases, Wi-Fi passwords, text messages, contact lists, photos, browser cookies, call history, location data, and various account details. The stolen data is then encrypted and transmitted to a dynamic network of command-and-control (C2) servers.

A redeployed version of the malware, observed in August, introduced a dedicated cryptocurrency wallet theft capability. This enhanced functionality specifically targets the iPhone keychain to extract seed phrases and mnemonic information from cryptocurrency wallets. These recovery phrases grant attackers full control over a victim’s digital assets, making this incident far more financially devastating than a typical data breach.

The attackers have continuously refined their tactics, refreshing filenames and staging components while old files remain accessible, complicating detection and takedown efforts. This behavior is consistent with other package ecosystem threats, where seemingly benign code can surreptitiously collect sensitive information post-installation.

What You Should Do

  • For Website Operators:
    • Immediately remove any untrusted or suspicious themes from your content management systems.
    • Thoroughly review all front-end scripts for unauthorized modifications or injected code.
    • Rotate all credentials handled on the affected host.
    • Inspect network activity for any of the indicators of compromise (IoCs) listed below.
    • Developers should pin and meticulously review Composer dependencies, including themes and assets, as client-side code executes with the same impact as server-side code.
  • For iPhone Users:
    • Prioritize and apply all available iOS updates immediately. Devices running iOS 18.7.3 (iOS 18 line) or iOS 26.2 and later are currently protected from this specific exploit chain.
    • Be cautious of unsolicited redirects, especially to gambling or unfamiliar sites, when browsing.
    • Consider using a reputable ad blocker and script blocker for enhanced browser security.
  • For Security Teams:
    • Block all listed network indicators of compromise (IoCs) at your perimeter.
    • Actively monitor for suspicious page loaders, hidden iframes, and unusual browser requests within your network traffic.
    • Ensure all managed iPhones are updated to the latest available iOS versions to mitigate known vulnerabilities.
    • Educate users on the risks of <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/95f0d62b-1a54-49de-b7ff-e95fddbc436acc24a654092f5205b2c5bd3208b126b2c2754ac63e7aea22298/Hackers-Use-Malicious-Website-Themes-to-Steal-Crypto-Wallet-Seeds-From-iPhones.pdf?AWSAccessKeyId=ASIA2F3EMEYE7YOAS7JZ&Signature=86PoZVH4DDuJcxM67FMMsmbKpLU%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEN%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwE

      Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

      Tags:

      AttackCVEExploitHackerPatchSecurityThreatzero-day

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Cisco Routers Vulnerable to State-Sponsored Attacks, Critical Infrastructure at Risk

Next Post

Critical Vulnerability in Popular npm Package Exposes Users to Supply Chain Attacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Attackers Target AWS Root Accounts at 150+ Organizations with Password Spraying
September 1, 2026
Broadcom Unveils VMware AI Factory for Secure Enterprise AI Deployment
August 31, 2026
Critical D-Link Router Flaws Let Attackers Change Admin Password, Steal Wi-Fi Credentials
August 31, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us