13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
A group linked to Vietnamese operators has been deploying a campaign targeting unpatched iPhones via malicious Composer theme packages. These packages inject JavaScript to install spyware, leveraging WebKit vulnerabilities (CVE-2025-31277 and CVE-2025-43529) to steal keychain data, Wi-Fi passwords, SMS databases, photos, browser cookies, location history, and cryptocurrency wallet seeds from devices running iOS 18.4 through 18.6.x. The campaign utilizes Funnull infrastructure, previously sanctioned by the U.S. for romance baiting scams, and aims to redirect visitors to gambling and adult content sites.
A campaign targeting unpatched iPhones has been identified, utilizing malicious Composer theme packages to install spyware. The threat actors, believed to be operating from Vietnam, are leveraging six malicious Packagist packages – vsmov, vsphim, haiau009, chilltvcms, and ophimcms – to inject JavaScript into Vietnamese movie and comic streaming sites. This JavaScript then initiates a WebKit-to-kernel exploit chain, exploiting CVE-2025-31277 (Patched in version 18.6) and CVE-2025-43529 (Patched in versions 18.7.3 and 26.2) to install spyware on iOS devices running versions 18.4 through 18.6.x.
Once installed, the spyware collects a wide range of sensitive data, including keychain databases, Wi-Fi passwords, SMS databases, photos, browser cookies, location history, account databases, and cryptocurrency wallet seeds from wallets like Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX. The final payload encrypts this data and uploads it via HTTPS POST /upload to a rotating pool of command and control domains, including cloudfareintcdn[.]com/wd-status.html.
The threat actors have been redeploying the entire iOS chain around August 12, 2026, with a new payload designed to steal iOS Keychain cryptocurrency wallet seeds. The campaign also redirects visitors to gambling and adult content sites.
Socket security researchers discovered that the same five vendor namespaces have published additional theme packages without active payloads, but these can be activated through ‘Custom JS’ fields. Site operators using OphimCMS or KKPhim are advised to check for installed packages, remove them, rotate credentials, and audit shipped jQuery and theme scripts for indicators of compromise. The campaign is linked to a Vietnamese-operated group, and Funnull, an entity sanctioned by the U.S. last May for facilitating romance baiting scams that led to over $200 million in cryptocurrency losses, hosts the iOS exploit infrastructure.
