VMTech
Discuss a project

13 Packagist Themes Used to Target Unpatched iPhones

13 Packagist Themes Used to Target Unpatched iPhones

Malicious Composer themes target iPhone visitors

Security researchers have identified 13 malicious Composer theme packages on Packagist that inject JavaScript into Vietnamese movie and comic streaming sites. The packages target sites that install the libraries and can serve a spyware chain to visitors using unpatched iPhones.

Socket researcher Kush Pandya said the injected code performs two operations: a mobile ad-fraud and gambling-redirect chain, and an iPhone-specific WebKit-to-kernel exploit chain ending in spyware. The campaign is an expansion of activity Socket documented in March 2026, when six packages posing as OphimCMS themes redirected users, exfiltrated URLs, injected advertisements and delivered a second-stage payload through Funnull-hosted infrastructure.

Packages and exploit chain

The 13 packages span five vendor namespaces: vsmov, vsphim, haiau009, chilltvcms and ophimcms. They include theme-dy, theme-rrdyw, theme-motchill, theme-vsmov, theme-heovl, theme-thempho, kkphim-legend, kkphim-motchill, theme-legend and theme-pcc.

On an iPhone, the injected JavaScript creates a hidden iframe to identify the device's iOS version and load an operating-system-specific exploit. The chain weaponizes CVE-2025-31277, patched in iOS 18.6, and CVE-2025-43529, patched in iOS 18.7.3 and 26.2. Socket compared the approach with the DarkSword exploit kit.

The payload moves from the WebContent sandbox into the GPU process, then uses the AppleM2ScalerCSCDriver IOKit user client to reach the kernel and gain read and write privileges. Apple addressed the kernel escape flaw in iOS and macOS 26.1.

Data collection extends to wallet theft

Once successful, the final payload collects keychain databases, Wi-Fi passwords, SMS data, contacts, Photos, browser cookies, call and location history, and account databases. It encrypts collected information with AES and uploads it through HTTPS POST requests to a rotating set of command-and-control domains. The exploitation worker reports progress to cloudfareintcdn[.]com/wd-status.html.

Socket observed the full iOS chain being redeployed around August 12, 2026, chiefly against iOS 18.4 through 18.6.x. The new payload adds theft of cryptocurrency wallet seeds and mnemonics from the iOS Keychain, querying material associated with Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet and OKX.

The same vendor namespaces also published additional packages without an active payload during analysis, but their Custom JS fields could activate malicious code rendered across every page. Attribution remains unclear, although commit metadata timestamps suggest a Vietnamese-operated group. The exploit hosts use Funnull infrastructure, an entity sanctioned by the United States in May for facilitating romance-baiting scams.

Actions for site operators

Operators using OphimCMS or KKPhim should check for the named packages, remove any that are installed, rotate credentials and audit shipped jQuery and theme scripts for indicators of compromise. The incident shows that theme dependencies can expose both site operators and mobile visitors, so businesses should inventory third-party packages, review browser-delivered code and keep managed iPhones on supported patched releases.

#cybersecurity#iossecurity#supplychain#packagist
Open analytics
On the site 1 views
min read 4 01.09.2026
Instagram

13 Packagist Themes Used to Target Unpatched iPhones

Open the post on Instagram ↗