A sophisticated campaign of malware has been uncovered, targeting unpatched iPhones and exploiting a vulnerability in their package manager, Packagist, to steal sensitive information from cryptocurrency wallet users. The attack, which was discovered on August 25th, affects any iPhone running iOS 14 or earlier that has not been updated to the latest version.
The malicious packages, 13 in total, were uploaded to the popular open-source repository Packagist and masqueraded as legitimate software updates for commonly used apps. Once installed, these packages would then gain access to a user’s sensitive data, including cryptocurrency wallet seeds, by exploiting a vulnerability in the iPhone’s package manager. This allowed attackers to bypass even password-protected wallets, giving them direct access to valuable crypto assets.
Packagist is a service that allows developers to easily share and manage open-source software packages for various programming languages, including PHP. Its vulnerability was only recently discovered, and it has since been patched. However, many iPhone users may still be at risk if they have not updated their devices in recent weeks. This highlights the importance of keeping mobile operating systems up-to-date with the latest security patches.
The attackers behind this campaign were likely after cryptocurrency wallets because they contain sensitive information such as seeds or private keys that can unlock large sums of money. With these details in hand, hackers could drain the contents of a wallet without needing to crack its password-protected defenses. This is particularly concerning for iPhone users who store cryptocurrencies on their devices.
The attackers’ modus operandi is a prime example of how identity exposure can unlock active attack paths. In this case, they used cross-domain privilege escalation – exploiting vulnerabilities in multiple layers of software and hardware – to gain access to sensitive information. Understanding these tactics is crucial for security professionals and individuals alike, as it highlights the importance of securing not only individual devices but also the broader ecosystem.
To protect themselves from similar attacks, iPhone users should ensure their operating system is updated to the latest version and avoid installing untrusted software packages. It’s also essential for developers to stay vigilant about vulnerabilities in open-source repositories like Packagist, as even seemingly harmless packages can pose significant risks if exploited by malicious actors.
In light of this campaign, we advise all iPhone users who haven’t updated their devices recently to do so immediately and enable two-factor authentication on any cryptocurrency wallets they use. Additionally, developers should prioritize patching vulnerabilities in open-source software repositories and regularly review the security of their dependencies. By taking proactive measures, individuals can safeguard themselves from the next wave of sophisticated cyber threats.
Source: The Hacker News — 2026-09-01