Packagist Themes Deliver iOS Spyware, Steal Crypto

Thirteen malicious theme packages on the PHP package repository Packagist are turning popular Vietnamese movie and comic streaming sites into launchpads for iOS spyware and cryptocurrency wallet theft, researchers warn[1][3][5]. The trojanised Composer themes inject JavaScript into every page viewed on affected sites, exposing visitors on unpatched iPhones to a WebKit-to-kernel exploit chain that installs surveillance malware and steals sensitive data, including wallet seed phrases[1][3].

Socket’s Threat Research Team traced the activity to 13 Composer packages published across five vendor namespacesβ€”vsmov, vsphim, haiau009, chilltvcms and ophimcmsβ€”that pose as legitimate themes for Vietnamese-language streaming platforms built on OphimCMS and KKPhim[1][3][5]. Package names such as theme-dy, theme-rrdyw, theme-motchill, theme-vsmov, theme-heovl, theme-thempho, kkphim-legend, kkphim-motchill, theme-legend and theme-pcc were all found to contain malicious front-end assets rather than just styling code[1]. Once installed, the injected JavaScript runs two parallel operations: a mobile ad-fraud and gambling redirect chain targeting visitors on phones, and a more sophisticated exploit path that fires only when it detects iOS Safari on vulnerable devices[1][3].

On unpatched iPhones, the exploit sequence abuses WebKit bugs to gain code execution in the browser and then chains into a kernel-level escape, granting the spyware extensive access to the device[1][3]. Researchers report that the payload exfiltrates keychain entries, SMS messages, photos, contacts and location data, and it specifically targets popular mobile crypto wallets including Bitget, Phantom, Trust Wallet and OKX in order to capture seed phrases and keystore files[3][5]. Researchers say Apple has addressed the underlying bugs in recent iOS and macOS releases, but devices that have not installed the latest security updates remain exposed to compromise when visiting affected sites[1][3].

The discovery builds on earlier work that uncovered six malicious Packagist themes in the ophimcms namespace, which shipped trojanised jQuery libraries that exfiltrated URLs, injected ads and redirected mobile traffic through infrastructure tied to FUNNULL Technology[2][4]. Socket researchers now describe the 13-theme cluster as a continuation of that campaign, noting overlapping domain patterns and telemetry that link the new gambling redirects and iOS spyware delivery to the same broader FUNNULL-associated ecosystem[1][4][7]. While no specific threat group has been formally attributed, the reuse of sanctioned infrastructure and the focus on monetisation via ad-fraud, gambling traffic and crypto theft suggest an organised actor with both financial motives and technical sophistication[2][4][7].

Following disclosure, the malicious Composer theme versions have been flagged on Packagist, and private repository services now refuse to serve listed malware artefacts to Composer clients, returning error codes instead of distribution files[1][9]. Packagist’s security advisory system assigns internal PKSA identifiers to compromised packages, enabling tools such as Composer 2.10 to automatically exclude flagged versions from dependency resolution so they cannot be installed in fresh deployments[11][13]. Site operators using OphimCMS, KKPhim or similarly themed stacks are being urged to audit their Composer manifests for any of the named packages, remove or replace affected themes, and treat impacted servers as potentially compromised once the malicious JavaScript has executed[1][2][4].

The incident underscores a broader pattern of supply-chain abuse on Packagist, which has recently included a campaign that republished malicious versions of Laravel localisation libraries to steal cloud and crypto credentials, as well as a separate attack that quietly added Linux backdoors to eight PHP packages via GitHub releases[10][14]. For defenders, the Vietnamese theme compromise is a reminder that seemingly low-risk front-end dependencies can conceal high-impact payloads, and that securing mobile users now requires both aggressive patching of iOS devices and continuous monitoring of server-side package ecosystems for signs of tampering[1][3][12].

References

  1. 13 Malicious Packagist Themes Deliver iOS Spyware That …
  2. 6 malicious Packagist OphimCMS themes ship trojanised …
  3. 13 malicious Packagist themes install iOS spyware that…
  4. 6 Malicious Packagist Themes Ship Trojanized jQuery and …
  5. Hackers Use Malicious Website Themes to Steal Crypto …
  6. Socket (@SocketSecurity) / X
  7. Security settings
  8. Laravel Lang Supply Chain Advisory – Snyk
  9. Composer 2.10 Release
  10. Malicious Composer Packages on Packagist: 2026 Report
  11. Security Advisories
  12. Packagist Supply Chain Attack Infects 8 Packages Using GitHub …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply