The record
Written from the 1 report below. Nothing here is unsourced.
- Security researchers found 13 malicious Composer theme packages on Packagist that inject JavaScript into Vietnamese movie and comic streaming websites.
- The injected code runs a mobile gambling-redirect and ad-fraud scheme on all visitors, and on iPhones deploys a WebKit-to-kernel exploit chain that installs spyware.
- The spyware targets iPhones running iOS 18.4 through 18.6.x and steals keychain databases, Wi-Fi passwords, SMS data, contacts, photos, location history, and cryptocurrency wallet seeds from apps like Trust Wallet, Phantom, and OKX.
- The exploit chain relies on WebKit flaws patched in iOS 18.6, 18.7.3, and 26.1, so updated iPhones are not affected.
- Website operators using OphimCMS or KKPhim should check for these packages and remove them, since both the sites and their visitors are victims of the campaign.
What to watch next
- Whether the 13 packages are removed from Packagist and whether more trojanized themes emerge from the same five vendor namespaces.
- Confirmation of which CVE identifier matches the kernel escape flaw patched in iOS 26.1.
- Any enforcement or attribution action against the Vietnamese-operated group and the Funnull-hosted exploit infrastructure.
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Kush Pandya
Socket security researcher
2 quotes · 1 outlet
“The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect chain, and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware”
In the article
…theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. " The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect chain, and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware ," Socket security researcher Kush Pandya said. The activity is assessed to be part of a campaign that was first documented by the application security company back in March 2026 that leveraged six malicious Packagist…
“On success, the final payload uses the kernel read to collect keychain databases, Wi-Fi passwords, the SMS database, the address book, Photos, browser cookies, call history, location history, and account databases, encrypts them with AES, and uploads them over HTTPS POST /upload to a rotating pool of command and control domains”
In the article
…had already been patched in iOS 26.1 and macOS 26.1 before receiving their report. It's suspected to be CVE-2025-43398, CVE-2025-43510, or CVE-2025-43520, all of which were kernel-related bugs fixed late last year. " On success, the final payload uses the kernel read to collect keychain databases, Wi-Fi passwords, the SMS database, the address book, Photos, browser cookies, call history, location history, and account databases, encrypts them with AES, and uploads them over HTTPS POST /upload to a rotating pool of command and control domains ," Pandya explained. "The worker beacons exploitation progress to cloudfareintcdn[.]com/wd-status.html." The threat actors behind the campaign have been found to redeploy the whole iOS chain around August 12, 2026,…
Coverage1
All filed from India
Named Vietnam · United States · Apple · Bitget · BitKeep · Bitpie · OKX · Packagist · Phantom · Tonkeeper · Trust Wallet · Funnull · Kush Pandya · Socket
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
