Cybersecurity researchers identified 13 malicious Composer theme packages on Packagist that inject JavaScript into Vietnamese streaming sites to deploy spyware and steal data from unpatched iOS devices.
Key Points
- Malicious packages target OphimCMS and KKPhim themes, enabling ad fraud, gambling redirects, and sophisticated iOS spyware deployment.
- The exploit chain weaponizes WebKit vulnerabilities CVE-2025-31277 and CVE-2025-43529 to bypass sandbox protections and gain kernel-level access.
- Attackers exfiltrate sensitive data including keychain databases, Wi-Fi passwords, SMS history, photos, and cryptocurrency wallet seeds.
- The campaign specifically targets iOS versions 18.4 through 18.6.x, affecting devices ranging from iPhone XS to iPhone 16.
- Infrastructure used in the attacks is linked to Funnull, an entity previously sanctioned by the U.S. for facilitating large-scale cryptocurrency scams.