Slow Fog: ComeCome delivery app suspected of embedding malicious SDK, methods similar to the FomoPeek coin theft incident
The founder of Slow Fog, Yu Xian, disclosed that following the previous FomoPeek App poisoning and theft incident, a food delivery app named ComeCome (comecome.icu) has been found to implement attacks using similar methods. FomoPeek versions v1.1-1.2 contain a malicious SDK that integrates 8 types of iOS kernel exploit schemes, which can automatically select attack methods based on device model and system version. The known affected iOS versions cover iOS 12--18.7 and 26--26.1.
After a successful attack, it can break through the iOS sandbox mechanism, thereby stealing assets from cryptocurrency wallets. Yu Xian warned that such threats may also affect iPad and Mac devices, and advised users to immediately update to the latest iOS version and remain highly vigilant against apps from unknown sources.






