Simply visiting a streaming site is enough for your crypto and personal data to be stolen!

Published Reading time: 4 minutes Cyber ​​Attacks & Data Breaches

Cybersecurity researchers have discovered 13 malicious theme packages on Packagist, which are being used on movie and comic book streaming websites in Vietnam. The packages can inject JavaScript into pages and launch an attack on unpatched iPhones, aiming to install spyware and steal seed phrases from crypto wallets.

Simply visiting a streaming site is enough to steal your crypto and personal data! - Image 1

According to Socket's Kush Pandya, the code added to websites performs two different functions. All visitors are taken through a chain of redirects to mobile ad fraud and gambling sites. iPhone users are also faced with an exploit chain that starts in WebKit, reaches the kernel, and installs spyware.

13 malicious packages on Packagist threaten unupdated iPhones with spyware and crypto seed phrase theft - Image 2

The activity appears to be a continuation of a campaign that Socket had recorded in March 2026. At that time, six malicious packages appeared as themes for OphimCMS and were used to redirect, harvest URLs, insert ads, and distribute a second payload from infrastructure hosted on Funnull. The payload led visitors to websites with gambling and adult content.

The 13 packages belong to five vendor namespaces:

  • vsmov: theme-dy, theme-rrdyw, theme-motchill, theme-vsmov
  • vsphim: theme-heovl, theme-thempho
  • haiau009: kkphim-legend, kkphim-motchill
  • chilltvcms: theme-legend
  • ophimcms: theme-dy, theme-motchill, theme-pcc, theme-rrdyw

The attack on unupdated iPhones

On iPhones, the modified Composer theme adds a hidden iframe that detects the iOS version and loads the corresponding variant of the exploit. The attack exploits WebKit vulnerabilities CVE-2025-31277, fixed in iOS 18.6, and CVE-2025-43529, fixed in versions 18.7.3 and 26.2. The chain is reminiscent of how the DarkSword exploit kit works.

First, the payload escapes the WebContent sandbox and is transferred to the GPU process. Then, a second stage gains access to the kernel via the AppleM2ScalerCSCDriver IOKit user client and ultimately obtains read and write permissions. Apple reportedly fixed the kernel escape issue in iOS and macOS 26.1.

If the attack is successful, the spyware exploits kernel access to collect Keychain databases, Wi-Fi passwords, SMS database, contacts, photos, browser cookies, call and location history, and account databases. The data is encrypted with AES and sent via HTTPS POST to /upload, using a changing set of command and control domains. The progress of the exploit is sent to cloudfareintcdn[.]com/wd-status.html.

The attackers reintroduced the entire attack chain to iOS around August 12, 2026. The newer version primarily targeted devices running iOS 18.4 to 18.6.x and added a feature to steal seed phrases and mnemonics from the iOS Keychain. The malware seeks out data for Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX wallets, expanding data collection to directly steal hardware that can be used to access crypto wallets.

Socket reports that the same five vendor namespaces also include other themes, which did not have an active payload at the time of analysis. However, they are configured so that the malicious code can be activated via the “Custom JS” fields, which appear on every page of the websites.

It is not known who is behind the campaign. Researchers believe it is likely linked to a group operating out of Vietnam, based on timestamps in the commit metadata. The servers hosting the iOS exploits operate on infrastructure owned by Funnull, an entity that the US imposed sanctions on last May for allegedly facilitating romance baiting scams that led to losses of over $200 million in cryptocurrency.

Socket warns that a visitor using iPhone XS through iPhone 16 and iOS 18.6.x or earlier can, through a page in mobile Safari, expose Keychain, Wi-Fi passwords, SMS, photos, contacts, cookies, location history, account databases, and seed phrases from crypto wallets. At the same time, all visitors from mobile devices face redirects to gambling websites and ad insertion.

Website administrators using OphimCMS or KKPhim are urged to check if they have any of these packages installed and remove them if found. Socket also recommends changing login details and checking jQuery scripts and themes for signs of tampering.

Hacks.gr on Google Set it as a preferred source for cybersecurity updates.
Preferred source

READ ALSO

Recommended readings from Hacks.gr to continue.

Participate in the discussion

Comments should remain on topic. Your email address will not be published.

0 / 2000

0 / 50

Your comments will not be published if:

  • 1. They cause "DoS" to the community with irrelevant or repetitive comments.
  • 2. They try to "phish" other users' information.
  • 3. They contain "zero-day" insults and slurs.
  • 4. Contain "malware" advertisements for products or services.
  • 5. Your comments should be sweet and friendly, not like malicious cookies trying to mislead us!