Malicious Composer themes turned sites into iPhone spyware

Socket found 13 malicious Packagist Composer themes across five vendor namespaces that injected JavaScript into Vietnamese movie and comic streaming sites, turning those pages into a delivery path for ad fraud and iPhone spyware. The team says the set expanded from six OphimCMS themes to 13 packages and that the payloads were redeployed after disclosure. The malicious code lives in the theme assets a site installs with Composer, so every visitor gets attacker-controlled JavaScript from the real site itself. On iPhones, that page code can then push through WebKit and into a kernel exploit chain that installs spyware and steals device data, including crypto wallet seeds. For operators, the exposure is not limited to the server that hosts the theme; the site itself becomes the malicious distributor, and any unpatched iPhone that visited it can carry the downstream risk. Apple says the kernel escape was already fixed in iOS and macOS 26.1, but the site-side supply chain and the visitor risk remain the important part of the map.

Part of the PlainSec briefing for 2026-08-31

Editions

CVEs

Sources