- Researchers discovered 13 malicious Composer theme packages on Packagist targeting Vietnamese streaming sites with JavaScript injection.
- The attack deploys ad-fraud and, on unpatched iPhones, a WebKit-to-kernel exploit chain that installs spyware.
- The iOS exploit chain weaponizes two WebKit vulnerabilities and has been updated to steal cryptocurrency wallet seeds.
- The campaign is linked to infrastructure provided by Funnull, an entity sanctioned by the U.S. for facilitating romance baiting scams.
Cybersecurity researchers at Socket have identified a set of 13 malicious Composer theme packages on Packagist designed to inject JavaScript into Vietnamese movie and comic streaming sites. The trojanized packages initiate a mobile ad-fraud and gambling-redirect chain, and on iPhones, a WebKit-to-kernel exploit chain that installs spyware, according to security researcher Kush Pandya.
The activity builds on a campaign first documented in March 2026 involving six malicious packages posing as OphimCMS themes. The complete set of packages spans five vendor namespaces, including vsmov, vsphim, haiau009, chilltvcms, and ophimcms.
On iPhones, the attack inserts a hidden iframe to determine the iOS version and loads an exploit chain targeting two WebKit vulnerabilities: CVE-2025-31277 and CVE-2025-43529. The payload then escapes the WebContent sandbox and reaches the kernel through the AppleM2ScalerCSCDriver IOKit user client, ultimately obtaining read and write privileges.
The final payload uses kernel read access to collect keychain databases, Wi-Fi passwords, SMS, photos, cookies, and location history, encrypting them with AES and uploading them to command and control domains. The threat actors redeployed the iOS chain around August 12, 2026, adding an iOS Keychain cryptocurrency wallet seed and mnemonic stealer targeting wallets like Bitget, Phantom, and Trust Wallet.
Socket notes the campaign is believed to be operated by a Vietnamese group, with exploit hosts running on infrastructure from Funnull, an entity sanctioned by the U.S. for facilitating romance baiting scams causing over $200 million in cryptocurrency losses. Site operators using OphimCMS or KKPhim are advised to check for and remove any malicious packages, rotate credentials, and audit theme scripts for indicators of compromise.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
