13 Malicious Packagist Themes Deliver iOS Spyware and Steal Crypto Wallet Seeds

· Original article ↗

Summary

Socket found 13 trojanized Composer themes that inject gambling redirects and, on vulnerable iPhones, a WebKit-to-kernel exploit chain delivering spyware that steals device data and cryptocurrency wallet seeds.

Key points

  • The 13 malicious themes span five Packagist vendor namespaces and target sites built with the Vietnamese OphimCMS and KKPhim systems.
  • Trojanized JavaScript is served to site visitors; mobile users also face gambling and ad-fraud redirects.
  • On vulnerable iPhones, staged loaders deliver WebKit exploits CVE-2025-31277 and CVE-2025-43529, followed by GPU-process and kernel escapes.
  • The spyware collects keychain data, Wi-Fi passwords, messages, contacts, photos, browser cookies, location history, and other personal data; its redeployed version also steals seeds for seven crypto wallets.
  • Operators redeployed the iOS chain under new filenames in August 2026; the reported exploit tables target iOS 18.4–18.6.x devices.
  • Apple confirmed the kernel escape was fixed in iOS and macOS 26.1; the article says the WebKit entry points were fixed in iOS 18.7.3 and iOS 26.2.
  • Socket advises operators to remove themes from the five named namespaces, rotate affected credentials, review dependencies, block indicators, and update vulnerable iPhones.

Article Details

Attack Vectors
  • Threat actors republished OphimCMS and KKPhim themes under their own Packagist vendor namespaces, retaining the project scaffolding while trojanizing front-end JavaScript served to site visitors.
  • The injected loaders target mobile visitors and use platform and referrer checks to avoid desktop browsers, bots, and direct visits.
  • One branch injects mobile ads and redirects visitors through gambling infrastructure. On iPhones, another branch loads staged WebKit exploits, pivots through the GPU process, and uses a kernel escape to install spyware.
  • The spyware collects device and account data. A redeployed payload also queries the keychain for cryptocurrency-wallet seeds and mnemonics.
  • A separately attributed gambling operation uses npm packages containing encoded configuration as a dead-drop for changing backend domains.
Defensive Notes
  • Site operators should remove themes from vsmov, vsphim, haiau009, chilltvcms, and ophimcms, rotate credentials handled on the host, and inspect shipped jQuery and theme scripts for appended loaders and network indicators.
  • Developers should pin and review Composer dependencies, including front-end assets, and scrutinize new or low-reputation vendor namespaces.
  • Security teams should block the reported network indicators and hunt for the session-storage keys rce_locked and uid, staggered iframe loading, status beacons, and wallet-theft strings such as keychain_query_bitget.
  • The article recommends moving iPhones off iOS 18.6.x and earlier. It states that devices updated to iOS 26.2 or later, or iOS 18.7.3 on the iOS 18 line, are not exposed to the known stages.

Indicators of compromise

TypeIndicatorContext
DOMAINabfdns[.]comName-server domain identified for the campaign's newer front.
DOMAINabfedgecanme[.]comNewer front for a campaign host.
DOMAINcdn1[.]aiDelegated front infrastructure for the exploit delivery control plane.
DOMAINcloudfareintcdn[.]comDomain used for spyware exploitation-progress beacons.
DOMAINcre-ads[.]comDomain listed under gambling and ad-fraud indicators.
DOMAINdq87771[.]comExample backend domain for the separately attributed gambling tenant.
DOMAINfunnull01[.]vipPublished FUNNULL indicator to which a sibling gambling-tenant domain CNAMEs.
DOMAINgaledns[.]comName-server domain identified for the campaign's newer front.
DOMAINiiauuw[.]comSecond hop in the separate gambling tenant's backend-domain CNAME cloak.
DOMAINkanejwo[.]comFirst hop in the separate gambling tenant's backend-domain CNAME cloak.
DOMAINlsmzt[.]ccInfrastructure through which the gambling-image host resolves.
DOMAINnqsaaskw[.]comControl-plane domain through which the second-stage host resolves.
DOMAINxemphimlau[.]comDestination of a malicious theme script's devtools-detection redirect.
DOMAINyunray[.]aiFUNNULL front infrastructure into which delivery and exfiltration hosts CNAME-cloak.
EMAILclemenciajohn74@gmail[.]comCommitter email listed among threat-actor handles for the malicious theme publishers.
EMAILdev[.]cuongnguyen@gmail[.]comCommitter email listed among threat-actor handles for the malicious theme publishers.
EMAILnguyenhai[.]tran[.]009@gmail[.]comCommitter email listed among threat-actor handles for the malicious theme publishers.
EMAILtuwibu2021@gmail[.]comCommitter email listed among threat-actor handles for the malicious theme publishers.
EMAILxuxuthoi01@gmail[.]comCommitter email listed among threat-actor handles for the malicious theme publishers.
HOSTNAMEcdn[.]data-2919[.]comHost listed as exploit-delivery infrastructure.
HOSTNAMEcdn[.]data-2920[.]comExploit-delivery host that serves the next JavaScript stage.
HOSTNAMEim[.]ue8im[.]comHost serving images for the injected gambling banner.
HOSTNAMEv7[.]kkphimplayer7[.]comCampaign host behind the newer front.
HOSTNAMEwww[.]0liwevrhxdc3s2xk00[.]comListed exfiltration C2 host.
HOSTNAMEwww[.]39rwcybep-20pwozhvdrzzy[.]netListed exfiltration C2 host.
HOSTNAMEwww[.]5wg3w278e3oamlohmcinrkh[.]liveListed exfiltration C2 host.
HOSTNAMEwww[.]cloudfareintcdn[.]comCloudflare-impersonating exploit-stage host.
HOSTNAMEwww[.]dlosdekr1u18msmov51[.]netListed exfiltration C2 host.
HOSTNAMEwww[.]ex0x40vmi8qyccxq[.]netListed exfiltration C2 host.
HOSTNAMEwww[.]ioa7xqmhiz26fv5e[.]infoListed exfiltration C2 host.
HOSTNAMEwww[.]isbo31w1o7xk3fztvmgpbv[.]appListed exfiltration C2 host.
HOSTNAMEwww[.]jhflt6l0dwminsl494836rb[.]orgListed exfiltration C2 host.
HOSTNAMEwww[.]kp2-3ur6pe4r8i2hj5[.]comListed exfiltration C2 host.
HOSTNAMEwww[.]ljot1cem6jhzfu53yb9aj3h[.]appListed exfiltration C2 host.
HOSTNAMEwww[.]ncalb1rzb2rq5-3zdx1[.]appListed exfiltration C2 host.
HOSTNAMEwww[.]ov86ayb0fe4ep2b92-645o[.]comListed exfiltration C2 host.
HOSTNAMEwww[.]qdh71-y6j7vxgw046v4cvgga[.]liveListed exfiltration C2 host.
HOSTNAMEwww[.]sx3cjniwo1bmtqs0vlj-va2f[.]appListed exfiltration C2 host.
HOSTNAMEwww[.]sx8vuz4smtdol7pg[.]comListed exfiltration C2 host.
HOSTNAMEwww[.]t9ffxu6zhf915fadjv1[.]appListed exfiltration C2 host.
HOSTNAMEwww[.]vutjsf0sd9sdqt2rkzvgzv9a[.]orgListed exfiltration C2 host.
HOSTNAMEwww[.]w4iunvbdvjof39q-3[.]netListed exfiltration C2 host.
HOSTNAMEwww[.]xtpj2bzxip6iq7n3bnz[.]infoListed exfiltration C2 host.
HOSTNAMEwww[.]zfu4n4kxgmx32hsqg[.]ccListed exfiltration C2 host.
IPV423[.]225[.]48[.]20Second gambling-redirect host, which forwards visitors to a landing page.
IPV423[.]225[.]52[.]67First gambling-redirect host linked from the injected mobile banner.
SHA25660b6771958cb7e553994ba6752f108575ba70e02d24affb51d8936a17eb0bf5eHash of exploit-stage start-view.html.
SHA25692c7d246d2c163c076f783dcc19f87f5b9b9ac301b106b87a7aaea9346ce0052Hash of iOS 18.4–18.5 RCE stage a84snnb6pknt3aflt01r.js.
SHA2569d6b58886189c0e23f706c32d3d8dda97b0b6d927ece6de07270813f070295b5Hash of spyware payload 4ap5xpu18z70wwslqybu.js.
SHA256d9530e8cd79ac7b3d02b04e05426653afca7075fcf7424eec4d59c6e95745933Hash of renderer loader a4tt4g37f36gdd7q7kdc.js.
SHA256de539a63cbe27bbd4a7db30fc796cd6dc5309c02ef5e60a3c5cf0835e5601283Hash of iOS 18.6-and-later worker qljbd9a1h4a83gw8lxcj.js.
SHA256f2fdfddbc436acc24a654092f5205b2c5bd3208b126b2c2754ac63e7aea22298Hash of kernel-escape stage 921w48jmeqvt3ygn0wwx.js.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationLoaders concealed a stage URL with base64 encoding, while one theme shipped ionCube-encrypted account-system code.T1041 · Exfiltration Over C2 ChannelThe spyware encrypted collected data and uploaded it to rotating command-and-control domains.T1068 · Exploitation for Privilege EscalationAfter renderer exploitation, stages pivoted through the GPU process and used a kernel escape.T1071.001 · Web ProtocolsThe payload used HTTPS POST for uploads and sent exploitation-progress web beacons.T1102 · Web ServiceA separately attributed tenant used npm packages as an encoded configuration dead-drop for current gambling backend domains.T1140 · Deobfuscate/Decode Files or InformationA theme loader decoded its concealed second-stage URL before creating a script element.T1189 · Drive-by CompromiseAn iPhone visitor could encounter the exploit chain simply by loading an affected site's page.T1195.001 · Compromise Software Dependencies and Development ToolsOperators trojanized Composer theme dependencies so installing sites served malicious front-end assets.T1203 · Exploitation for Client ExecutionThe chain exploited WebKit vulnerabilities to obtain arbitrary read and write in the WebContent renderer.T1480 · Execution GuardrailsLoaders checked platform and referrer, and exploit stages selected payloads by iOS version.T1552.001 · Credentials In FilesThe spyware read sensitive stores from hardcoded paths, including keychain databases containing wallet material.T1608.001 · Upload MalwareOperators staged JavaScript exploit components and a spyware payload on delivery infrastructure.T1608.004 · Drive-by TargetTrojanized themes turned Vietnamese streaming sites into drive-by delivery locations for visitors.

CVE

People

Vendors

Products

Bitgetan iOS-keychain crypto-wallet seed and mnemonic stealer. It queries the keychain for wallet material from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX (keychain_query_bitget,BitKeepcrypto-wallet seed and mnemonic stealer. It queries the keychain for wallet material from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX (keychain_query_bitget, keychain_query_bitpie,Bitpieseed and mnemonic stealer. It queries the keychain for wallet material from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX (keychain_query_bitget, keychain_query_bitpie,ComposerSocket’s Threat Research Team found 13 malicious Composer theme packages on Packagist, published across five vendor namespaces, that inject JavaScript into every page of the Vietnamese movie and comic streaming sitesiOSchain, and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware. We reported the iOS chain to Apple and coordinated disclosure. Apple confirmed the kernel escape was already fixed in iOS andKKPhimhaiau009: kkphim-legend, kkphim-motchillmacOSchain to Apple and coordinated disclosure. Apple confirmed the kernel escape was already fixed in iOS and macOS 26.1 before our report, and the two WebKit entry points are public and listed in CISA's Known ExploitedOKXthe keychain for wallet material from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX (keychain_query_bitget, keychain_query_bitpie, keychain_query_phantom, keychain_query_tonkeeper,OphimCMSKnown Exploited Vulnerabilities catalog. Our earlier research covered six themes under a single vendor (ophimcms); this expands the confirmed set to 13 packages across five vendors and follows the chain through to thePackagistSocket’s Threat Research Team found 13 malicious Composer theme packages on Packagist, published across five vendor namespaces, that inject JavaScript into every page of the Vietnamese movie and comic streaming sitesPhantomseed and mnemonic stealer. It queries the keychain for wallet material from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX (keychain_query_bitget, keychain_query_bitpie, keychain_query_phantom,Tonkeepermnemonic stealer. It queries the keychain for wallet material from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX (keychain_query_bitget, keychain_query_bitpie, keychain_query_phantom,Trust Walletstealer. It queries the keychain for wallet material from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX (keychain_query_bitget, keychain_query_bitpie, keychain_query_phantom,WebKitoperations against a site’s visitors: a mobile ad-fraud and gambling-redirect chain, and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware. We reported the iOS chain to Apple and coordinated

Tools

Countries

Industries

Related Articles