Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices.
“The injected code runs two operations against a site’s visitors: a mobile ad-fraud and gambling-redirect chain, and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware,” Socket security researcher Kush Pandya said.
The activity is assessed to be part of a campaign that was first documented by the application security company back in March 2026 that leveraged six malicious Packagist packages posing as OphimCMS themes to redirect visitors, exfiltrate URLs, inject ads, and serve from Funnull-hosted infrastructure a second-stage payload to lead victims to gambling and adult content sites.
The complete set of packages, which span five vendor namespaces, is below –
- vsmov: theme-dy, theme-rrdyw, theme-motchill, theme-vsmov
- vsphim: theme-heovl, theme-thempho
- haiau009: kkphim-legend, kkphim-motchill
- chilltvcms: theme-legend
- ophimcms: theme-dy, theme-motchill, theme-pcc, theme-rrdyw
At a high level, the trojanized Composer theme injects JavaScript that runs a mobile gambling and ad-fraud redirect and, on iPhones, a Funnull-hosted WebKit-to-kernel exploit chain ending in spyware and cryptocurrency-wallet theft.
The iOS attack chain is designed to insert a hidden iframe element that determines the iOS version and loads an operating system-specific version of the exploit. Specifically, it weaponizes two WebKit vulnerabilities — CVE-2025-31277 (Patched in version 18.6) and CVE-2025-43529 (Patched in versions 18.7.3 and 26.2) — in a manner that’s analogous to the DarkSword exploit kit.
The payload then pivots out of the WebContent sandbox into the GPU process, followed by a second stage that reaches the kernel through the AppleM2ScalerCSCDriver IOKit user client and ultimately obtains read and write privileges. Apple is said to have addressed the kernel escape flaw in iOS and macOS 26.1.
“On success, the final payload uses the kernel read to collect keychain databases, Wi-Fi passwords, the SMS database, the address book, Photos, browser cookies, call history, location history, and account databases, encrypts them with AES, and uploads them over HTTPS POST /upload to a rotating pool of command and control domains,” Pandya explained. “The worker beacons exploitation progress to cloudfareintcdn[.]com/wd-status.html.”
The threat actors behind the campaign have been found to redeploy the whole iOS chain around August 12, 2026, mainly targeting iOS devices running versions 18.4 through 18.6.x with a new payload that adds an iOS Keychain cryptocurrency wallet seed and mnemonic stealer.
The malware queries the password store for wallet material from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX, extending beyond device data collection to direct financial theft.
Socket said the same five vendor namespaces have published additional theme packages that carry no active payload at the time of analysis, although they have been configured such that the malicious code could be activated via “Custom JS” fields rendered into every page on the websites.
It’s not clear who is behind the campaign, although it’s believed to be the work of a Vietnamese-operated group based on commit metadata timestamps. It’s worth pointing out that the iOS exploit hosts run on infrastructure provided by Funnull, an entity sanctioned by the U.S. last May for facilitating romance baiting scams that led to over $200 million in cryptocurrency losses.
“A visitor to a site that installed one of these themes, on an iPhone that has not been updated past iOS 18.6.x (iPhone XS through iPhone 16), can have their keychain, Wi-Fi passwords, SMS, Photos, contacts, cookies, location history, account databases, and cryptocurrency wallet seeds collected and exfiltrated by loading a page in mobile Safari,” Socket said.
“Every mobile visitor is also subject to the gambling-redirect and ad-injection chain. The site operators are victims too: they shipped the trojanized theme unknowingly and served the payload to their own users.”
To counter the threat, site operators using OphimCMS or KKPhim are advised to check if they have installed any of the aforementioned packages, remove them if found, rotate credentials, and audit shipped jQuery and theme scripts for indicators of compromise.






