Security researchers have uncovered 13 malicious Composer theme packages on Packagist that are being used to target visitors of Vietnamese movie and comic streaming websites. The packages inject harmful JavaScript into websites that install them and can expose visitors to both advertising redirects and a serious iPhone spyware attack. The campaign mainly affects sites using OphimCMS and KKPhim, where operators may unknowingly install compromised themes. Researchers from Socket found that the malicious themes are spread across five vendor namespaces, including vsmov, vsphim, haiau009, chilltvcms, and ophimcms.

The injected code performs two main activities depending on the visitor and device. Mobile users can be sent through gambling and advertising redirect chains, while selected iPhone users can face a much more dangerous WebKit-to-kernel exploit chain. The attack uses a hidden iframe to identify the iOS version running on the device and then delivers an exploit suited to that version. Researchers found that the chain abuses two WebKit vulnerabilities, CVE-2025-31277 and CVE-2025-43529, which were already addressed by Apple in newer software versions. The attack then moves beyond the browser sandbox toward deeper system access.

After successfully progressing through the exploit chain, the spyware can collect a wide range of sensitive information from the affected iPhone. This includes keychain databases, Wi-Fi passwords, SMS messages, contacts, photos, browser cookies, call history, location history, and account databases. The stolen information is encrypted and sent to rotating command-and-control servers through HTTPS requests. Researchers said the campaign was redeployed around August 12, 2026, with a newer payload aimed at iPhones running iOS 18.4 through 18.6.x. The targeted devices include models from the iPhone XS generation through the iPhone 16 family.

The latest version of the spyware adds another major threat by specifically searching for cryptocurrency wallet recovery information. Researchers found routines designed to look for wallet seeds and mnemonic information belonging to Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX. These recovery phrases are extremely sensitive because they can potentially allow someone to regain access to cryptocurrency funds. This means the campaign has moved beyond ordinary information theft and now has a direct financial motivation. The same malicious infrastructure has also been connected to FUNNULL, an entity that has previously been associated with large-scale online scam infrastructure.

Apple had already fixed the two WebKit vulnerabilities used as entry points in newer releases, while the kernel escape component was reportedly addressed in iOS and macOS 26.1 before Socket reported the campaign. The WebKit flaws were fixed in iOS 18.7.3 and iOS 26.2, with corresponding Apple security updates. Researchers said devices running these newer patched versions are not affected by the known exploit stages used in this campaign. However, users who continue running older vulnerable versions remain at greater risk when visiting compromised websites. Keeping iPhones updated is therefore an important protection against this attack.

Website operators using OphimCMS or KKPhim are advised to check their Composer dependencies for the 13 identified packages and remove them if they are present. They should also rotate credentials, review website JavaScript, and look for suspicious scripts or loaders that may have been added to legitimate files. Developers should carefully review and pin Composer dependencies because front-end themes can execute code directly in visitors’ browsers. The incident shows how a compromised software package can turn an ordinary website into an attack platform, allowing criminals to target visitors with spyware, steal sensitive information, and ultimately seek cryptocurrency wallet recovery data.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news