{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3oredhatenterprise_linux_eus8.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*","cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*","cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*","cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*","cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*","cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*","cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*","cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_aus:8.2:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_aus:8.4:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_aus:8.6:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_els:7.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_eus:9.4:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2025-31277"},{"cvss":8.8,"id":"CVE-2025-43529"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["iOS (\u003c 18.7.3)","macOS (\u003c 26.1)"],"_cs_severities":["high"],"_cs_tags":["supply-chain","mobile-malware","web-security","cryptocurrency-theft","ios","spyware"],"_cs_type":"advisory","_cs_vendors":["Apple"],"content_html":"\u003cp\u003eResearchers have identified 13 malicious Composer theme packages hosted on Packagist that target Vietnamese movie and comic streaming sites. These packages are part of a broader campaign involving at least five vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms) that inject malicious JavaScript into websites. When a user visits an infected site on an unpatched iOS device (specifically iOS versions 18.4 through 18.6.x), the script triggers a multi-stage exploit chain. This campaign leverages infrastructure previously linked to the Funnull entity to facilitate browser-based exploitation. The final payload achieves kernel-level access on the target iPhone, enabling the exfiltration of sensitive databases, including SMS, browser cookies, Photos, and cryptocurrency wallet seeds from applications like Bitget, Phantom, and Trust Wallet. This threat is particularly notable for its use of supply chain compromise to reach end-users and the automation of financial theft via mobile browser exploitation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eSite administrators unknowingly install a trojanized Composer theme package from the Packagist repository.\u003c/li\u003e\n\u003cli\u003eThe theme injects malicious JavaScript into every page served to website visitors.\u003c/li\u003e\n\u003cli\u003eThe JavaScript performs browser-side environment fingerprinting to identify the visitor's iOS version.\u003c/li\u003e\n\u003cli\u003eThe script retrieves a platform-specific exploit payload hosted on external infrastructure (Funnull).\u003c/li\u003e\n\u003cli\u003eThe browser executes an exploit chain weaponizing CVE-2025-31277 and CVE-2025-43529 to escape the WebContent sandbox.\u003c/li\u003e\n\u003cli\u003eThe exploit pivots to the GPU process and triggers a kernel vulnerability (AppleM2ScalerCSCDriver) to gain read/write privileges.\u003c/li\u003e\n\u003cli\u003eThe final spyware payload extracts the iOS Keychain, SMS, Photos, and wallet seeds, then encrypts them using AES.\u003c/li\u003e\n\u003cli\u003eThe stolen data is exfiltrated via HTTPS POST to a rotating pool of command-and-control domains.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign affects users of mobile Safari on iOS devices running vulnerable firmware (iOS 18.4 through 18.6.x). If successful, attackers gain complete access to the device's personal data, including Wi-Fi passwords, call history, location, and cryptocurrency assets. The use of infrastructure associated with previously sanctioned entities indicates a high-stakes financial motivation. While the exact number of victims is not publicly quantified, the campaign targets high-traffic streaming sites, suggesting a broad scope of potential compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eSite operators using OphimCMS or KKPhim must audit dependencies for the identified vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms) and remove all unauthorized themes immediately.\u003c/li\u003e\n\u003cli\u003eBlock the identified C2 domain \u0026quot;cloudfareintcdn.com\u0026quot; at the network perimeter and DNS resolver level.\u003c/li\u003e\n\u003cli\u003eEnforce OS updates for all mobile devices; prioritize patching iOS to 18.7.3 or later and macOS to 26.1 or later to mitigate CVE-2025-31277 and CVE-2025-43529.\u003c/li\u003e\n\u003cli\u003eUsers should review permissions for cryptocurrency wallet applications and rotate credentials for affected accounts if their devices were running vulnerable iOS versions during the period of exposure.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-01T15:09:46Z","date_published":"2026-09-01T15:09:46Z","id":"https://feed.craftedsignal.io/briefs/2026-09-packagist-ios-spyware/","summary":"Threat actors are distributing 13 malicious Composer themes via Packagist to compromise streaming websites and deploy a WebKit-to-kernel exploit chain against iOS visitors for data exfiltration and cryptocurrency wallet theft.","title":"Malicious Packagist Composer Themes Deploying iOS Spyware","url":"https://feed.craftedsignal.io/briefs/2026-09-packagist-ios-spyware/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}