Packagist themes deliver iPhone spyware that steals crypto seeds
Socket Threat Research found 13 malicious Composer theme packages on Packagist that inject JavaScript on Vietnamese streaming sites and, on unpatched iPhones running iOS 18.4 to 18.6.x, push spyware that now also steals crypto wallet seeds from the iOS Keychain. Site operators are victims too.

Socket Threat Research, in a report by Kush Pandya published August 31, documented 13 malicious Composer theme packages on Packagist that inject visitor-facing JavaScript on Vietnamese movie and comic streaming sites. On unpatched iPhones, specifically those still on iOS 18.4 to 18.6.x, that injected code goes well past ad fraud and into spyware that now also steals cryptocurrency wallet seeds. The streaming sites running these themes are victims too: their pages are compromised to serve the payload to their own visitors.
This is a vendor research writeup you can act on, not a CISA advisory and not a vendor self-disclosure.
Thirteen packages, five namespaces
The malicious packages sit across five vendor namespaces: vsmov, vsphim, haiau009, chilltvcms and ophimcms. A Socket note in March 2026 had flagged six packages under ophimcms alone; this run widens the set and follows the payload all the way to the iPhone. If you run OphimCMS or KKPhim and pulled a theme from any of those five namespaces, treat it as untrusted.
Two visitors, two payloads
The injected script sorts visitors. Ordinary mobile users get a run-of-the-mill ad-fraud and gambling-redirect chain. iPhone users on out-of-date iOS get the real payload: a WebKit-to-kernel exploit chain that, once it lands, collects keychain databases, Wi-Fi passwords, the SMS database, contacts, Photos, browser cookies, and call and location history, encrypts them, and posts them to rotating command-and-control servers.
On August 12 the operators redeployed and roughly doubled the payload, adding an iOS Keychain wallet-seed and mnemonic stealer aimed at seven wallets: Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet and OKX. On a phone that falls to the chain, that turns a browsing session into a drained wallet.
Why this is not a mass event
Two facts keep the spyware from being an everyone-problem. The chain only stages against iPhones on iOS 18.4 through 18.6.x (iPhone XS through iPhone 16); Socket found no version tables for iOS 18.7 or the iOS 26 line. And Apple told Socket the kernel escape was already closed in iOS and macOS 26.1, before the report went out, so a device on iOS 26.2 or 18.7.3 and later sits outside the known stages. The two WebKit bugs named in the code, CVE-2025-31277 and CVE-2025-43529, are both already in CISA's Known Exploited Vulnerabilities catalog. This is an n-day against phones that never updated, not a zero-day against current iOS.
The hosting adds context without being a nationality claim. The iOS stages run on FUNNULL infrastructure, the Triad Nexus provider that OFAC sanctioned in May 2025 for facilitating more than $200 million in crypto scams; roughly 20 exfiltration domains were bulk-registered in a single burst on June 2 and were still live when Socket published. Theme commit metadata points to Vietnamese-operated CMS forks. That is shared bad infrastructure, not a label for everyone who ever touched these packages.
What to do now
Site operators on OphimCMS or KKPhim: audit installed themes against those five namespaces, remove anything that matches, rotate credentials handled on the host, and read your theme and jQuery scripts for appended loaders. Developers: pin and review Composer theme and asset packages the same way you would any code that runs in a user's browser. Security teams: block Socket's indicators, hunt for the session-storage keys rce_locked and uid, and push every iPhone off iOS 18.6.x and earlier. Even a fully patched visitor still gets the gambling redirect, so cleaning the site matters even where the spyware cannot land.
The single most useful move today is to check whether your streaming CMS pulled a theme from vsmov, vsphim, haiau009, chilltvcms or ophimcms, and to get every iPhone on your network past iOS 18.6.x. Those two steps close both ends of this campaign. For related supply-chain risk, see the malicious Virtualizor update used to hijack BGP, and on the cost of running lagging software, the emergency PaperCut zero-day patch.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free