13 Malicious Packagist Themes Deliver iOS Spyware and Steal Crypto Wallet Seeds

Summary
Socket found 13 trojanized Composer themes that inject gambling redirects and, on vulnerable iPhones, a WebKit-to-kernel exploit chain delivering spyware that steals device data and cryptocurrency wallet seeds.
Key points
- The 13 malicious themes span five Packagist vendor namespaces and target sites built with the Vietnamese OphimCMS and KKPhim systems.
- Trojanized JavaScript is served to site visitors; mobile users also face gambling and ad-fraud redirects.
- On vulnerable iPhones, staged loaders deliver WebKit exploits CVE-2025-31277 and CVE-2025-43529, followed by GPU-process and kernel escapes.
- The spyware collects keychain data, Wi-Fi passwords, messages, contacts, photos, browser cookies, location history, and other personal data; its redeployed version also steals seeds for seven crypto wallets.
- Operators redeployed the iOS chain under new filenames in August 2026; the reported exploit tables target iOS 18.4–18.6.x devices.
- Apple confirmed the kernel escape was fixed in iOS and macOS 26.1; the article says the WebKit entry points were fixed in iOS 18.7.3 and iOS 26.2.
- Socket advises operators to remove themes from the five named namespaces, rotate affected credentials, review dependencies, block indicators, and update vulnerable iPhones.
Article Details
- Attack Vectors
- Threat actors republished OphimCMS and KKPhim themes under their own Packagist vendor namespaces, retaining the project scaffolding while trojanizing front-end JavaScript served to site visitors.
- The injected loaders target mobile visitors and use platform and referrer checks to avoid desktop browsers, bots, and direct visits.
- One branch injects mobile ads and redirects visitors through gambling infrastructure. On iPhones, another branch loads staged WebKit exploits, pivots through the GPU process, and uses a kernel escape to install spyware.
- The spyware collects device and account data. A redeployed payload also queries the keychain for cryptocurrency-wallet seeds and mnemonics.
- A separately attributed gambling operation uses npm packages containing encoded configuration as a dead-drop for changing backend domains.
- Defensive Notes
- Site operators should remove themes from vsmov, vsphim, haiau009, chilltvcms, and ophimcms, rotate credentials handled on the host, and inspect shipped jQuery and theme scripts for appended loaders and network indicators.
- Developers should pin and review Composer dependencies, including front-end assets, and scrutinize new or low-reputation vendor namespaces.
- Security teams should block the reported network indicators and hunt for the session-storage keys rce_locked and uid, staggered iframe loading, status beacons, and wallet-theft strings such as keychain_query_bitget.
- The article recommends moving iPhones off iOS 18.6.x and earlier. It states that devices updated to iOS 26.2 or later, or iOS 18.7.3 on the iOS 18 line, are not exposed to the known stages.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | abfdns[.]com | Name-server domain identified for the campaign's newer front. |
| DOMAIN | abfedgecanme[.]com | Newer front for a campaign host. |
| DOMAIN | cdn1[.]ai | Delegated front infrastructure for the exploit delivery control plane. |
| DOMAIN | cloudfareintcdn[.]com | Domain used for spyware exploitation-progress beacons. |
| DOMAIN | cre-ads[.]com | Domain listed under gambling and ad-fraud indicators. |
| DOMAIN | dq87771[.]com | Example backend domain for the separately attributed gambling tenant. |
| DOMAIN | funnull01[.]vip | Published FUNNULL indicator to which a sibling gambling-tenant domain CNAMEs. |
| DOMAIN | galedns[.]com | Name-server domain identified for the campaign's newer front. |
| DOMAIN | iiauuw[.]com | Second hop in the separate gambling tenant's backend-domain CNAME cloak. |
| DOMAIN | kanejwo[.]com | First hop in the separate gambling tenant's backend-domain CNAME cloak. |
| DOMAIN | lsmzt[.]cc | Infrastructure through which the gambling-image host resolves. |
| DOMAIN | nqsaaskw[.]com | Control-plane domain through which the second-stage host resolves. |
| DOMAIN | xemphimlau[.]com | Destination of a malicious theme script's devtools-detection redirect. |
| DOMAIN | yunray[.]ai | FUNNULL front infrastructure into which delivery and exfiltration hosts CNAME-cloak. |
clemenciajohn74@gmail[.]com | Committer email listed among threat-actor handles for the malicious theme publishers. | |
dev[.]cuongnguyen@gmail[.]com | Committer email listed among threat-actor handles for the malicious theme publishers. | |
nguyenhai[.]tran[.]009@gmail[.]com | Committer email listed among threat-actor handles for the malicious theme publishers. | |
tuwibu2021@gmail[.]com | Committer email listed among threat-actor handles for the malicious theme publishers. | |
xuxuthoi01@gmail[.]com | Committer email listed among threat-actor handles for the malicious theme publishers. | |
| HOSTNAME | cdn[.]data-2919[.]com | Host listed as exploit-delivery infrastructure. |
| HOSTNAME | cdn[.]data-2920[.]com | Exploit-delivery host that serves the next JavaScript stage. |
| HOSTNAME | im[.]ue8im[.]com | Host serving images for the injected gambling banner. |
| HOSTNAME | v7[.]kkphimplayer7[.]com | Campaign host behind the newer front. |
| HOSTNAME | www[.]0liwevrhxdc3s2xk00[.]com | Listed exfiltration C2 host. |
| HOSTNAME | www[.]39rwcybep-20pwozhvdrzzy[.]net | Listed exfiltration C2 host. |
| HOSTNAME | www[.]5wg3w278e3oamlohmcinrkh[.]live | Listed exfiltration C2 host. |
| HOSTNAME | www[.]cloudfareintcdn[.]com | Cloudflare-impersonating exploit-stage host. |
| HOSTNAME | www[.]dlosdekr1u18msmov51[.]net | Listed exfiltration C2 host. |
| HOSTNAME | www[.]ex0x40vmi8qyccxq[.]net | Listed exfiltration C2 host. |
| HOSTNAME | www[.]ioa7xqmhiz26fv5e[.]info | Listed exfiltration C2 host. |
| HOSTNAME | www[.]isbo31w1o7xk3fztvmgpbv[.]app | Listed exfiltration C2 host. |
| HOSTNAME | www[.]jhflt6l0dwminsl494836rb[.]org | Listed exfiltration C2 host. |
| HOSTNAME | www[.]kp2-3ur6pe4r8i2hj5[.]com | Listed exfiltration C2 host. |
| HOSTNAME | www[.]ljot1cem6jhzfu53yb9aj3h[.]app | Listed exfiltration C2 host. |
| HOSTNAME | www[.]ncalb1rzb2rq5-3zdx1[.]app | Listed exfiltration C2 host. |
| HOSTNAME | www[.]ov86ayb0fe4ep2b92-645o[.]com | Listed exfiltration C2 host. |
| HOSTNAME | www[.]qdh71-y6j7vxgw046v4cvgga[.]live | Listed exfiltration C2 host. |
| HOSTNAME | www[.]sx3cjniwo1bmtqs0vlj-va2f[.]app | Listed exfiltration C2 host. |
| HOSTNAME | www[.]sx8vuz4smtdol7pg[.]com | Listed exfiltration C2 host. |
| HOSTNAME | www[.]t9ffxu6zhf915fadjv1[.]app | Listed exfiltration C2 host. |
| HOSTNAME | www[.]vutjsf0sd9sdqt2rkzvgzv9a[.]org | Listed exfiltration C2 host. |
| HOSTNAME | www[.]w4iunvbdvjof39q-3[.]net | Listed exfiltration C2 host. |
| HOSTNAME | www[.]xtpj2bzxip6iq7n3bnz[.]info | Listed exfiltration C2 host. |
| HOSTNAME | www[.]zfu4n4kxgmx32hsqg[.]cc | Listed exfiltration C2 host. |
| IPV4 | 23[.]225[.]48[.]20 | Second gambling-redirect host, which forwards visitors to a landing page. |
| IPV4 | 23[.]225[.]52[.]67 | First gambling-redirect host linked from the injected mobile banner. |
| SHA256 | 60b6771958cb7e553994ba6752f108575ba70e02d24affb51d8936a17eb0bf5e | Hash of exploit-stage start-view.html. |
| SHA256 | 92c7d246d2c163c076f783dcc19f87f5b9b9ac301b106b87a7aaea9346ce0052 | Hash of iOS 18.4–18.5 RCE stage a84snnb6pknt3aflt01r.js. |
| SHA256 | 9d6b58886189c0e23f706c32d3d8dda97b0b6d927ece6de07270813f070295b5 | Hash of spyware payload 4ap5xpu18z70wwslqybu.js. |
| SHA256 | d9530e8cd79ac7b3d02b04e05426653afca7075fcf7424eec4d59c6e95745933 | Hash of renderer loader a4tt4g37f36gdd7q7kdc.js. |
| SHA256 | de539a63cbe27bbd4a7db30fc796cd6dc5309c02ef5e60a3c5cf0835e5601283 | Hash of iOS 18.6-and-later worker qljbd9a1h4a83gw8lxcj.js. |
| SHA256 | f2fdfddbc436acc24a654092f5205b2c5bd3208b126b2c2754ac63e7aea22298 | Hash of kernel-escape stage 921w48jmeqvt3ygn0wwx.js. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationLoaders concealed a stage URL with base64 encoding, while one theme shipped ionCube-encrypted account-system code.T1041 · Exfiltration Over C2 ChannelThe spyware encrypted collected data and uploaded it to rotating command-and-control domains.T1068 · Exploitation for Privilege EscalationAfter renderer exploitation, stages pivoted through the GPU process and used a kernel escape.T1071.001 · Web ProtocolsThe payload used HTTPS POST for uploads and sent exploitation-progress web beacons.T1102 · Web ServiceA separately attributed tenant used npm packages as an encoded configuration dead-drop for current gambling backend domains.T1140 · Deobfuscate/Decode Files or InformationA theme loader decoded its concealed second-stage URL before creating a script element.T1189 · Drive-by CompromiseAn iPhone visitor could encounter the exploit chain simply by loading an affected site's page.T1195.001 · Compromise Software Dependencies and Development ToolsOperators trojanized Composer theme dependencies so installing sites served malicious front-end assets.T1203 · Exploitation for Client ExecutionThe chain exploited WebKit vulnerabilities to obtain arbitrary read and write in the WebContent renderer.T1480 · Execution GuardrailsLoaders checked platform and referrer, and exploit stages selected payloads by iOS version.T1552.001 · Credentials In FilesThe spyware read sensitive stores from hardcoded paths, including keychain databases containing wallet material.T1608.001 · Upload MalwareOperators staged JavaScript exploit components and a spyware payload on delivery infrastructure.T1608.004 · Drive-by TargetTrojanized themes turned Vietnamese streaming sites into drive-by delivery locations for visitors.
CVE
CVE-2025-31277The renderer stage weaponizes two WebKit vulnerabilities, annotated in the code as CVE-2025-31277 (iOS 18.4 to 18.5) and CVE-2025-43529 (iOS 18.6 and later). Both are now public, patched, and listed in CISA’s KnownCVE-2025-43529weaponizes two WebKit vulnerabilities, annotated in the code as CVE-2025-31277 (iOS 18.4 to 18.5) and CVE-2025-43529 (iOS 18.6 and later). Both are now public, patched, and listed in CISA’s Known ExploitedCVE-2026-43655struct carrying two IOSurface IDs. This driver and interface are the same ones disclosed publicly as CVE-2026-43655 (an AppleM2ScalerCSCDriver use-after-free fixed in iOS 26.5), and the public CVE-2026-43655
People
Vendors
Appleand, on iPhones, a WebKit-to-kernel exploit chain that installs spyware. We reported the iOS chain to Apple and coordinated disclosure. Apple confirmed the kernel escape was already fixed in iOS and macOS 26.1SocketSocket’s Threat Research Team found 13 malicious Composer theme packages on Packagist, published across five vendor namespaces, that inject JavaScript into every page of the Vietnamese movie and comic streaming sites
Products
Bitgetan iOS-keychain crypto-wallet seed and mnemonic stealer. It queries the keychain for wallet material from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX (keychain_query_bitget,BitKeepcrypto-wallet seed and mnemonic stealer. It queries the keychain for wallet material from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX (keychain_query_bitget, keychain_query_bitpie,Bitpieseed and mnemonic stealer. It queries the keychain for wallet material from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX (keychain_query_bitget, keychain_query_bitpie,ComposerSocket’s Threat Research Team found 13 malicious Composer theme packages on Packagist, published across five vendor namespaces, that inject JavaScript into every page of the Vietnamese movie and comic streaming sitesiOSchain, and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware. We reported the iOS chain to Apple and coordinated disclosure. Apple confirmed the kernel escape was already fixed in iOS andKKPhimhaiau009: kkphim-legend, kkphim-motchillmacOSchain to Apple and coordinated disclosure. Apple confirmed the kernel escape was already fixed in iOS and macOS 26.1 before our report, and the two WebKit entry points are public and listed in CISA's Known ExploitedOKXthe keychain for wallet material from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX (keychain_query_bitget, keychain_query_bitpie, keychain_query_phantom, keychain_query_tonkeeper,OphimCMSKnown Exploited Vulnerabilities catalog. Our earlier research covered six themes under a single vendor (ophimcms); this expands the confirmed set to 13 packages across five vendors and follows the chain through to thePackagistSocket’s Threat Research Team found 13 malicious Composer theme packages on Packagist, published across five vendor namespaces, that inject JavaScript into every page of the Vietnamese movie and comic streaming sitesPhantomseed and mnemonic stealer. It queries the keychain for wallet material from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX (keychain_query_bitget, keychain_query_bitpie, keychain_query_phantom,Tonkeepermnemonic stealer. It queries the keychain for wallet material from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX (keychain_query_bitget, keychain_query_bitpie, keychain_query_phantom,Trust Walletstealer. It queries the keychain for wallet material from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX (keychain_query_bitget, keychain_query_bitpie, keychain_query_phantom,WebKitoperations against a site’s visitors: a mobile ad-fraud and gambling-redirect chain, and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware. We reported the iOS chain to Apple and coordinated
Tools
DarkSwordtyped array). These renderer CVEs and the staging pattern overlap with the publicly documented “DarkSword” iOS exploit kit.Socket browser extensionin CI pipelines. Socket Firewall blocks known malicious packages before they are fetched. The Socket browser extension surfaces risk signals while browsing npm. Socket MCP prevents AI-assisted coding workflows fromSocket CLIApp scans pull request dependency changes and flags injected or obfuscated code before merge. The Socket CLI enforces allow and deny rules in CI pipelines. Socket Firewall blocks known malicious packages beforeSocket Firewallor obfuscated code before merge. The Socket CLI enforces allow and deny rules in CI pipelines. Socket Firewall blocks known malicious packages before they are fetched. The Socket browser extension surfaces riskSocket GitHub Apptrojanized front-end assets shipped inside packages, before they reach developer environments. The Socket GitHub App scans pull request dependency changes and flags injected or obfuscated code before merge. The SocketSocket MCPbefore they are fetched. The Socket browser extension surfaces risk signals while browsing npm. Socket MCP prevents AI-assisted coding workflows from introducing suspicious dependencies into your codebase.