TTO-2026-0901-003 · September 1, 2026 Supply ChainMobileCrypto Theft

13 Trojanized Packagist Themes Deliver WebKit-to-Kernel iPhone Exploit and Crypto Wallet Seed Theft to Streaming Site Visitors

packagist.orgsocket.dev13 malicious Composer themesVietnamese streaming sitesWebKit CVE-2025-31277 CVE-2025-43529Kernel escape via AppleM2ScalerCSCDriveriOS 18.4-18.6.xTrust Wallet Phantom OKX BitKeepGambling redirect for AndroidFUNNULL infrastructure

Summary

Socket Threat Research published analysis on September 1, 2026 of 13 malicious Composer theme packages distributed through Packagist, the PHP package repository, that turn Vietnamese movie and comic streaming websites into delivery infrastructure for iPhone spyware, cryptocurrency wallet seed theft, mobile gambling redirects, and advertising fraud. Site operators install the trojanized themes through the standard composer require command, unknowingly embedding malicious JavaScript in every page served to visitors. The package names include vsmov/theme-dy, vsmov/theme-rrdyw, vsphim/theme-heovl, haiau009/kkphim-legend, chilltvcms/theme-legend, and multiple ophimcms variants. The campaign runs two parallel operations. Android and iOS visitors are redirected to mobile gambling pages. iPhone visitors running iOS 18.4 through iOS 18.6.x face a more serious chain that weaponizes two public WebKit vulnerabilities, CVE-2025-31277 and CVE-2025-43529, to achieve arbitrary read and write inside the browser renderer, then pivots through the GPU process before escaping to the kernel via the AppleM2ScalerCSCDriver IOKit user client. Once kernel access is established, the payload harvests the iPhone keychain, extracting seed phrases and mnemonic recovery words from cryptocurrency wallets including Trust Wallet, Phantom, OKX, BitKeep, Bitpie, Bitget, and Tonkeeper. A redeployed version of the payload observed in August 2026 added targeted queries specifically for cryptocurrency wallet seed material. Both WebKit vulnerabilities have been patched in iOS 18.7.3 and iOS 26.2. The kernel escape vulnerability was fixed in iOS 26.1. Socket confirmed the campaign is hosted on FUNNULL content delivery infrastructure previously linked to pig-butchering fraud operations.

Timeline

DateEvent
Early 2026Socket identifies initial ophimcms malicious themes on Packagist — first phase of campaign
Mar 2026FUNNULL infrastructure linked to campaign — previously associated with pig-butchering fraud
Aug 2026Redeployed payload adds targeted cryptocurrency wallet seed phrase queries for Trust Wallet, Phantom, OKX, BitKeep, Bitpie, Bitget, Tonkeeper
Aug 2026CVE-2025-31277 and CVE-2025-43529 patched in iOS 18.7.3 and iOS 26.2 — kernel escape patched in iOS 26.1
Sep 1, 2026Socket publishes full analysis — 13 malicious packages confirmed across five Packagist namespaces

Domain Intelligence

DomainScoreDKIMSPFDMARCStatus
packagist.org85.0✓✓✓Live
socket.dev85.0✓✓✓Live
WarmBadge Intelligence Snapshot · Captured: September 1, 2026 UTC

Context

packagist.org scores 85.0 and socket.dev scores 85.0 — both above the trust threshold, consistent with an established package repository and a security research organization respectively. The attack against Packagist-hosted Composer themes follows the same structural pattern as the npm mirror phishing campaign documented in TTO-2026-0827-002: attackers exploit the implicit trust that developers and site operators place in established package infrastructure. A site operator who runs composer require against a package on Packagist has no reasonable expectation that the resulting theme will inject a WebKit-to-kernel exploit chain against their iPhone-using visitors. The attack surface is not the streaming site or its operator. It is the supply chain that delivers the site's front-end assets. The cryptocurrency wallet targets — Trust Wallet, Phantom, OKX, and five others — represent a targeted selection of the most widely used mobile self-custody wallets. Seed phrase theft from the iPhone keychain is permanent: unlike a password that can be changed, a seed phrase gives irrevocable access to every address derived from that wallet.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 1, 2026