Cybersecurity experts have recently uncovered a series of 13 malicious packages on Packagist, specifically designed to inject harmful JavaScript into Vietnamese movie and comic streaming platforms. These packages target unpatched iPhones, deploying spyware to extract sensitive information, including cryptocurrency wallet seeds.
How the Malicious Packages Operate
The threat is executed by injecting code that performs two main operations: redirecting mobile traffic for ad-fraud and gambling, and exploiting iPhones through a WebKit-to-kernel chain to install spyware. This was highlighted by security researcher Kush Pandya from Socket. The campaign traces back to March 2026, initially involving six Packagist packages masquerading as OphimCMS themes, which rerouted traffic and exfiltrated data.
The affected packages span across multiple namespaces including vsmov, vsphim, haiau009, chilltvcms, and ophimcms. These trojanized themes inject scripts that lead to spyware installations, ultimately resulting in the theft of cryptocurrency wallet information.
Details of the iOS Exploit Chain
The exploitation method involves inserting a hidden iframe to identify the iOS version and load a corresponding exploit. This attack leverages two known WebKit vulnerabilities, CVE-2025-31277 and CVE-2025-43529, akin to the techniques used in the DarkSword exploit kit. Apple has since patched these vulnerabilities in later iOS versions.
Once the attack is successful, the spyware gains access to the device’s kernel, allowing it to extract and encrypt sensitive data such as keychain databases, SMS logs, and browser cookies, which are then uploaded to remote servers.
Implications and Preventative Measures
The campaign saw a resurgence on August 12, 2026, with a new payload specifically targeting iOS devices with versions between 18.4 and 18.6.x. This payload seeks out cryptocurrency wallet data from several wallet apps, widening the impact from data theft to direct financial losses.
Despite the malicious nature of these packages, some additional theme packages published by the same vendors were found without active payloads but could be activated through specific site configurations. The campaign is suspected to be run by a Vietnamese group, with infrastructure linked to the sanctioned entity Funnull.
Website operators using sensitive themes like OphimCMS or KKPhim are urged to verify their installations, remove any suspicious packages, and conduct thorough security audits to mitigate potential threats. Regular updates and a vigilant approach to cybersecurity can help protect against such vulnerabilities.
