Medium Frontend infra hack Source: SlowMist Team

SlowMist Security Team identified a campaign targeting iOS Safari users on specific versions (18.4–18.6.2) via a fake VPS service landing page

SlowMist Security Team identified a campaign targeting iOS Safari users on specific versions (18.4–18.6.2) via a fake VPS service landing page. The decoy page loads JavaScript that screens for iPhones, potentially leading to asset theft from the DarkSword wallet.

Protocols
DarkSword
Confidence
High
First seen
4 Sep 2026, 11:08 UTC

Read the original report ↗ (opens in a new tab)