A sophisticated malware campaign has been uncovered, targeting unpatched iPhones and exploiting a vulnerability in their package management system. At least 13 malicious packages have been discovered on Packagist, a popular PHP library repository, which are designed to steal cryptocurrency wallet seeds from unsuspecting iPhone users.
The attack begins when an iPhone user installs one of the malicious packages, which is masquerading as legitimate software. Once installed, the malware gains access to the device’s package management system and starts searching for cryptocurrency wallets on the device. When it finds a wallet seed, the malware sends the sensitive information to its command-and-control server, allowing hackers to drain the user’s cryptocurrency funds.
The vulnerability being exploited is in the iPhone’s software update mechanism, which fails to properly validate packages from external sources like Packagist. This means that even if an iPhone user has not installed any malicious software directly, a compromised package can still be loaded onto their device through the app store or other channels. The attackers are likely exploiting this vulnerability to gain access to unpatched iPhones, as the latest iOS update is only available for devices running iOS 14 and later versions.
The scope of the attack appears to be significant, with at least 13 malicious packages discovered on Packagist in recent weeks. These packages have been downloaded thousands of times, suggesting that many iPhone users may already be infected without realizing it. Furthermore, some security experts warn that the malware may also be capable of spreading through other means, such as exploiting vulnerabilities in the iPhone’s Safari browser or even through physical attacks.
The attack highlights the importance of keeping software up-to-date and exercising caution when installing packages from external sources. Even if an iPhone user has not installed any malicious software directly, they may still be vulnerable to this type of attack if their device is not running the latest iOS version. To protect themselves, users should ensure that their devices are running the latest software and exercise caution when installing third-party apps or packages.
In light of this discovery, users who have installed any of the 13 malicious packages on Packagist should take immediate action to secure their devices. This includes updating their iPhone to the latest iOS version, scanning for malware using reputable security tools, and changing their cryptocurrency wallet seeds as a precautionary measure.
Source: The Hacker News — 2026-09-01