Security1 distinct publisher2 min readPublished
Socket says trojanized OphimCMS and KKPhim themes chain two WebKit bugs to an IOKit kernel escape on visitors' iPhones, turning a Composer dependency problem into wallet seed theft from people who only loaded a page.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The code path shifts the victim partway through: Composer resolves the theme on the server, the theme ships jQuery and page scripts, and those scripts then execute in the browser of everyone who visits. The iOS leg opens with a hidden iframe that reads the OS version and serves the matching build of the exploit [5], which is how one payload covers a spread of devices without burning itself on a patched one. Socket's researcher Kush Pandya describes two parallel operations in the injected code: the ad-fraud and gambling redirect for all mobile visitors, and the exploit chain for iPhones [2].
The patch versions here matter as much as the CVE numbers. Socket reports CVE-2025-31277 closed in iOS 18.6 and CVE-2025-43529 closed in 18.7.3 and 26.2 [6]. The August 12, 2026 redeployment aimed at 18.4 through 18.6.x [11]. So a phone that took the 18.6 update has the first bug shut and still sits below the 18.7.3 line for the second [3]. The kernel escape through the AppleM2ScalerCSCDriver IOKit user client is, in the source's hedged phrasing, addressed in iOS and macOS 26.1 [8], and 26.1 predates 26.2, which means an estate standardised on 26.1 has the kernel leg closed and one WebKit leg open [4].
Socket also found further themes from the same five namespaces carrying no live payload at analysis time, configured so code could be switched on through Custom JS fields that render into every page [13]. That amounts to staged capability rather than a finished attack, and pulling the thirteen named packages addresses only that slice of it. Socket's advice to OphimCMS and KKPhim operators runs to checking installs, removing what is found, rotating credentials, and auditing the jQuery and theme scripts they are shipping [18].
Attribution is thin and Socket says as much: a Vietnamese-operated group, inferred from commit metadata timestamps [14]. The infrastructure link carries more weight. The exploit hosts run on Funnull, sanctioned by the United States last May over romance baiting scams tied to more than $200 million in cryptocurrency losses [15]. The August payload reads the same way, querying the keychain for Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet and OKX material [12].
Per Socket, a streaming site with an audience on older iPhones, anything from an iPhone XS to an iPhone 16 left on 18.6.x, is a better delivery surface than a phishing run, because the visitor agreed to nothing beyond loading a page in mobile Safari [16].
Ranked by verification strength, evidence, and original report placement.
Researchers identified 13 malicious Composer theme packages on Packagist designed to inject JavaScript into Vietnamese movie and comic streaming sites that install them and initiate deployment of spyware aimed at unpatched iOS devices.
Socket researcher Kush Pandya said the injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect chain, and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware.
The packages span five vendor namespaces: vsmov (theme-dy, theme-rrdyw, theme-motchill, theme-vsmov), vsphim (theme-heovl, theme-thempho), haiau009 (kkphim-legend, kkphim-motchill), chilltvcms (theme-legend), and ophimcms (theme-dy, theme-motchill, theme-pcc, theme-rrdyw).
The activity is assessed as part of a campaign Socket first documented in March 2026, which used six malicious Packagist packages posing as OphimCMS themes to redirect visitors, exfiltrate URLs, inject ads and serve a Funnull-hosted second stage.
The iOS attack chain inserts a hidden iframe that determines the iOS version and loads an operating-system-specific version of the exploit.
The chain weaponises two WebKit vulnerabilities, CVE-2025-31277 (patched in version 18.6) and CVE-2025-43529 (patched in versions 18.7.3 and 26.2), in a manner analogous to the DarkSword exploit kit.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
Thirteen Packagist themes push mobile ad-fraud, with an iPhone-only kernel exploit chain1 distinct publisher
build
77 linked Firefox add-ons, one pipeline: store review is a checkpoint, not a control1 distinct publisher
build
Rewritten tags beat your pin: what laravel-lang says about Composer trust1 distinct publisher
invest
Your Landed Cost Is Being Litigated By Companies With $306,000 Problems1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor, unusually specific
The specificity is what carries this: a named IOKit user client, two CVEs with their exact patch versions, a beacon host and path, thirteen package names. Those are checkable assertions, and that is a genuine strength. The weakness is that nobody has checked them — Socket found it, The Hacker News relayed it, and Apple's advisory, Packagist's removal log and any second research team are all missing from the record.
Live campaign, unmeasured reach
Deployment is not in doubt — thirteen published packages, a re-shipped exploit chain in mid-August, and dormant siblings pre-wired for the next round all point to operators who expect to keep working. What is entirely absent is scale. Not one install figure, affected-site tally or victim count appears, so the campaign is demonstrably running and its blast radius is undocumented.
Restrained text, unstated scale
A headline about stolen crypto wallet seeds could easily outrun its evidence; this one mostly does not, because each dramatic step is pinned to a named flaw or driver and the attribution is explicitly left open. The overstatement is by omission. With no install counts anywhere, a reader cannot tell whether this touched three streaming sites or three hundred, and the story's own framing invites them to assume the larger number.
Vendor research, doubling as marketing
Socket sells scanning for precisely the registries where it found these packages, and this is the second chapter of a campaign it named and first published itself — good research and good positioning are the same artifact here. The Hacker News supplies distribution rather than scrutiny, printing the vendor's remediation checklist as the story's advice. Nothing suggests the findings are shaped by that, only that no disinterested party has looked.
Internally coherent, singly sourced
The pieces fit each other, which matters: the CVE patch levels, the 18.4 through 18.6.x targeting band and the 26.1 kernel fix line up into a consistent picture instead of pulling apart, and the partial-patch states follow from figures the reporting supplies. What holds this to the middle is structural — one relay of one vendor, an attribution the researchers reduce to commit timestamps, and no way to size the affected population.