MarsBit: "ComeCome" App Suspected of Bundling Malicious SDK in Attack Resembling FomoPeek Case
AI Market Summary
SlowMist's founder reported ComeCome (comecome.icu) using an attack pattern similar to the FomoPeek incident, embedding a malicious SDK that leverages multiple iOS kernel exploit techniques (reported affected versions spanning iOS 12–18.7) to bypass sandbox protections and steal crypto wallet assets. The disclosure heightens operational risk for retail users, potentially dampening near-term on-chain activity and sentiment, while increasing scrutiny of mobile wallet security and app-source hygiene.
Impact level
● Medium
Affected assets
BTC/USDT-0.29%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Huo Xing Cai Jing reported that Yu Xian, founder of cybersecurity firm SlowMist, said a new app dubbed ComeCome (comecome.icu) has been flagged for using tactics similar to those seen in the recent FomoPeek app poisoning and theft incident. ComeCome is presented as a food delivery app.
According to Yu, FomoPeek versions v1.1–1.2 embedded a malicious SDK that incorporated eight iOS kernel exploit techniques and automatically chose an attack path based on the device model and operating system version. The exploits are known to affect iOS versions ranging from iOS 12–18.7 and 26–26.1. Once exploitation succeeds, the attacker can bypass iOS sandbox protections to steal assets from cryptocurrency wallets.
Yu cautioned that the threat could also extend to iPad and Mac devices, urging users to update to the latest iOS version and to treat apps from untrusted sources with extreme caution.