According to Socket's Kush Pandya, the code added to websites performs two different functions. All visitors are taken through a chain of redirects to mobile ad fraud and gambling sites. iPhone users are also faced with an exploit chain that starts in WebKit, reaches the kernel, and installs spyware.

The activity appears to be a continuation of a campaign that Socket had recorded in March 2026. At that time, six malicious packages appeared as themes for OphimCMS and were used to redirect, harvest URLs, insert ads, and distribute a second payload from infrastructure hosted on Funnull. The payload led visitors to websites with gambling and adult content.
The 13 packages belong to five vendor namespaces:
vsmov:theme-dy,theme-rrdyw,theme-motchill,theme-vsmovvsphim:theme-heovl,theme-themphohaiau009:kkphim-legend,kkphim-motchillchilltvcms:theme-legendophimcms:theme-dy,theme-motchill,theme-pcc,theme-rrdyw
The attack on unupdated iPhones
On iPhones, the modified Composer theme adds a hidden iframe that detects the iOS version and loads the corresponding variant of the exploit. The attack exploits WebKit vulnerabilities CVE-2025-31277, fixed in iOS 18.6, and CVE-2025-43529, fixed in versions 18.7.3 and 26.2. The chain is reminiscent of how the DarkSword exploit kit works.
First, the payload escapes the WebContent sandbox and is transferred to the GPU process. Then, a second stage gains access to the kernel via the AppleM2ScalerCSCDriver IOKit user client and ultimately obtains read and write permissions. Apple reportedly fixed the kernel escape issue in iOS and macOS 26.1.
If the attack is successful, the spyware exploits kernel access to collect Keychain databases, Wi-Fi passwords, SMS database, contacts, photos, browser cookies, call and location history, and account databases. The data is encrypted with AES and sent via HTTPS POST to /upload, using a changing set of command and control domains. The progress of the exploit is sent to cloudfareintcdn[.]com/wd-status.html.
The attackers reintroduced the entire attack chain to iOS around August 12, 2026. The newer version primarily targeted devices running iOS 18.4 to 18.6.x and added a feature to steal seed phrases and mnemonics from the iOS Keychain. The malware seeks out data for Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX wallets, expanding data collection to directly steal hardware that can be used to access crypto wallets.
Socket reports that the same five vendor namespaces also include other themes, which did not have an active payload at the time of analysis. However, they are configured so that the malicious code can be activated via the “Custom JS” fields, which appear on every page of the websites.
It is not known who is behind the campaign. Researchers believe it is likely linked to a group operating out of Vietnam, based on timestamps in the commit metadata. The servers hosting the iOS exploits operate on infrastructure owned by Funnull, an entity that the US imposed sanctions on last May for allegedly facilitating romance baiting scams that led to losses of over $200 million in cryptocurrency.
Socket warns that a visitor using iPhone XS through iPhone 16 and iOS 18.6.x or earlier can, through a page in mobile Safari, expose Keychain, Wi-Fi passwords, SMS, photos, contacts, cookies, location history, account databases, and seed phrases from crypto wallets. At the same time, all visitors from mobile devices face redirects to gambling websites and ad insertion.
Website administrators using OphimCMS or KKPhim are urged to check if they have any of these packages installed and remove them if found. Socket also recommends changing login details and checking jQuery scripts and themes for signs of tampering.
Your comments will not be published if: