Return to Threats

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

thehackernews.com 2026-09-01 AI supply chain High

What Happened

Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. "The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect

Why It Matters

The report says 13 malicious Packagist Composer packages were found injecting JavaScript into Vietnamese streaming sites and helping deploy spyware aimed at unpatched iPhones, with code that also drives ad-fraud and gambling redirects. This is primarily a software supply chain compromise in a package ecosystem, not an AI-specific attack. RealGround analysis: the security implication is that organizations using third-party packages should strengthen dependency vetting, integrity checks, and incident response for poisoned upstream libraries.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html

Talk to AI CISO