<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3oredhatenterprise_linux_eus8.6/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 01 Sep 2026 15:09:46 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3oredhatenterprise_linux_eus8.6/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Malicious Packagist Composer Themes Deploying iOS Spyware</title><link>https://feed.craftedsignal.io/briefs/2026-09-packagist-ios-spyware/</link><pubDate>Tue, 01 Sep 2026 15:09:46 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-packagist-ios-spyware/</guid><description>Threat actors are distributing 13 malicious Composer themes via Packagist to compromise streaming websites and deploy a WebKit-to-kernel exploit chain against iOS visitors for data exfiltration and cryptocurrency wallet theft.</description><content:encoded><![CDATA[<p>Researchers have identified 13 malicious Composer theme packages hosted on Packagist that target Vietnamese movie and comic streaming sites. These packages are part of a broader campaign involving at least five vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms) that inject malicious JavaScript into websites. When a user visits an infected site on an unpatched iOS device (specifically iOS versions 18.4 through 18.6.x), the script triggers a multi-stage exploit chain. This campaign leverages infrastructure previously linked to the Funnull entity to facilitate browser-based exploitation. The final payload achieves kernel-level access on the target iPhone, enabling the exfiltration of sensitive databases, including SMS, browser cookies, Photos, and cryptocurrency wallet seeds from applications like Bitget, Phantom, and Trust Wallet. This threat is particularly notable for its use of supply chain compromise to reach end-users and the automation of financial theft via mobile browser exploitation.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Site administrators unknowingly install a trojanized Composer theme package from the Packagist repository.</li>
<li>The theme injects malicious JavaScript into every page served to website visitors.</li>
<li>The JavaScript performs browser-side environment fingerprinting to identify the visitor's iOS version.</li>
<li>The script retrieves a platform-specific exploit payload hosted on external infrastructure (Funnull).</li>
<li>The browser executes an exploit chain weaponizing CVE-2025-31277 and CVE-2025-43529 to escape the WebContent sandbox.</li>
<li>The exploit pivots to the GPU process and triggers a kernel vulnerability (AppleM2ScalerCSCDriver) to gain read/write privileges.</li>
<li>The final spyware payload extracts the iOS Keychain, SMS, Photos, and wallet seeds, then encrypts them using AES.</li>
<li>The stolen data is exfiltrated via HTTPS POST to a rotating pool of command-and-control domains.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The campaign affects users of mobile Safari on iOS devices running vulnerable firmware (iOS 18.4 through 18.6.x). If successful, attackers gain complete access to the device's personal data, including Wi-Fi passwords, call history, location, and cryptocurrency assets. The use of infrastructure associated with previously sanctioned entities indicates a high-stakes financial motivation. While the exact number of victims is not publicly quantified, the campaign targets high-traffic streaming sites, suggesting a broad scope of potential compromise.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Site operators using OphimCMS or KKPhim must audit dependencies for the identified vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms) and remove all unauthorized themes immediately.</li>
<li>Block the identified C2 domain &quot;cloudfareintcdn.com&quot; at the network perimeter and DNS resolver level.</li>
<li>Enforce OS updates for all mobile devices; prioritize patching iOS to 18.7.3 or later and macOS to 26.1 or later to mitigate CVE-2025-31277 and CVE-2025-43529.</li>
<li>Users should review permissions for cryptocurrency wallet applications and rotate credentials for affected accounts if their devices were running vulnerable iOS versions during the period of exposure.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>supply-chain</category><category>mobile-malware</category><category>web-security</category><category>cryptocurrency-theft</category><category>ios</category><category>spyware</category></item></channel></rss>