<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/13-malicious-packagist-themes-install-ios-spyware-that-steals-crypto-wallet-seeds-mjl26lgwo" -->

---
title: 13 malicious Packagist themes install iOS spyware that...
description: Socket&#x27;s Threat Research Team uncovered 13 malicious Composer/Packagist theme packages, spread across five vendor namespaces, that trojanize front-end assets...
canonical: https://daily.dev/posts/13-malicious-packagist-themes-install-ios-spyware-that-steals-crypto-wallet-seeds-mjl26lgwo
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: 13 malicious Packagist themes install iOS spyware that steals crypto wallet seeds | daily.dev
og:description: Socket&#x27;s Threat Research Team uncovered 13 malicious Composer/Packagist theme packages, spread across five vendor namespaces, that trojanize front-end assets...
og:url: https://daily.dev/posts/13-malicious-packagist-themes-install-ios-spyware-that-steals-crypto-wallet-seeds-mjl26lgwo
og:image: https://api.daily.dev/og/posts/mJl26LGwO.png
og:image:alt: 13 malicious Packagist themes install iOS spyware that steals crypto wallet seeds
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# 13 malicious Packagist themes install iOS spyware that steals crypto wallet seeds

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 0 upvotes · 0 comments

## Summary

Socket's Threat Research Team uncovered 13 malicious Composer/Packagist theme packages, spread across five vendor namespaces, that trojanize front-end assets on Vietnamese streaming sites built with OphimCMS and KKPhim (Laravel-based PHP CMSes). Injected JavaScript runs two attack chains: one redirects mobile users to ad-fraud and gambling sites, the other targets unpatched iPhones by chaining CVE-2025-31277, CVE-2025-43529, and a CVE-2026-43655 variant to escape WebKit into the kernel and install spyware that steals keychain data, SMS, photos, contacts, location, and crypto wallet seeds from Bitget, Phantom, Trust Wallet, and OKX. Apple patched the kernel escape in iOS/macOS 26.1; devices on iOS 26.2 or 18.7.3+ are safe, but older iPhones (XS through 16) on iOS 18.4-18.6.x remain exposed. The campaign runs on the sanctioned FUNNULL/Triad Nexus infrastructure previously linked to the Polyfill.io incident, with Vietnamese operators running the CMS packages and a separate Chinese gambling operation using npm as a config dead-drop. Site operators are urged to audit installed themes against the named namespaces, remove matches, rotate credentials, and update affected iPhones.

## Content

Socket's Threat Research Team found 13 malicious Composer/Packagist theme packages, spread across five vendor namespaces, that trojanize front-end assets for Vietnamese movie and comic streaming sites built on OphimCMS and KKPhim (both Laravel-based PHP CMSes).

The injected JavaScript runs two separate attack chains. The first redirects mobile visitors to ad-fraud and gambling sites. The second, more serious chain targets unpatched iPhones: it weaponizes CVE-2025-31277, CVE-2025-43529, and a variant of CVE-2026-43655 to escape WebKit into the kernel and install spyware.

Once installed, the spyware harvests keychain data, SMS messages, photos, contacts, and location history. It also specifically targets crypto wallet seeds and mnemonics from Bitget, Phantom, Trust Wallet, OKX, and others.

Apple confirmed the kernel escape was patched in iOS/macOS 26.1. Devices running iOS 26.2 or 18.7.3 and above are not exposed. Older iPhones (XS through 16) still on iOS 18.4 through 18.6.x remain at risk.

The campaign runs on FUNNULL (Triad Nexus) infrastructure, a sanctioned provider previously tied to the Polyfill.io supply chain incident. Attribution is split: independent Vietnamese-speaking theme operators appear responsible for the CMS packages, while a separate Chinese gambling operation is abusing npm as a configuration dead-drop.

If you run a site using these CMSes, audit your installed themes against the named vendor namespaces, remove any matches, rotate credentials, and update affected iPhones off vulnerable iOS versions.

## Questions this post answers

### Which iOS versions are vulnerable to the CVE-2025-31277 WebKit kernel escape used in the Packagist spyware campaign?

Older iPhones from the XS through the 16 running iOS 18.4 through 18.6.x remain exposed. Apple patched the underlying kernel escape, which chains CVE-2025-31277, CVE-2025-43529, and a CVE-2026-43655 variant, in iOS/macOS 26.1. Devices already updated to iOS 26.2 or 18.7.3 and above are not affected by this exploit chain.

_Developers tracking iOS security patches can follow CVE disclosures like this one on daily.dev._

### What crypto wallets are targeted by the spyware distributed through malicious Packagist theme packages?

The spyware specifically harvests seed phrases and mnemonics from Bitget, Phantom, Trust Wallet, OKX, and other crypto wallet apps, alongside keychain data, SMS messages, photos, contacts, and location history. It gets installed on unpatched iPhones after a WebKit-to-kernel escape triggered by trojanized JavaScript embedded in Composer theme packages for OphimCMS and KKPhim sites.

_Anyone building on crypto wallet integrations can track supply chain threats like this via daily.dev._

### How do I check if my Composer/Packagist project uses a malicious OphimCMS or KKPhim theme package?

Audit installed themes against the five malicious vendor namespaces identified by Socket's Threat Research Team, spanning 13 packages that trojanize front-end assets for Vietnamese streaming sites built on OphimCMS and KKPhim, both Laravel-based PHP CMSes. Remove any matching packages, rotate credentials, and update any iPhones exposed to the linked WebKit kernel exploit chain.

_PHP developers auditing dependencies for supply chain risks can follow reports like this on daily.dev._

## Similar posts on daily.dev

- [6 Malicious Packagist Themes Ship Trojanized jQuery and FUNN...](https://daily.dev/posts/6-malicious-packagist-themes-ship-trojanized-jquery-and-funn--bkmj35bje) · Socket · 0 upvotes · 0 comments
- [Snoops plant info-stealing malware on iPhones, Google warns](https://daily.dev/posts/snoops-plant-info-stealing-malware-on-iphones-google-warns-6bnlnyeuc) · The Register · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#ios](https://daily.dev/tags/ios), [#php](https://daily.dev/tags/php), [#crypto](https://daily.dev/tags/crypto), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/13-malicious-packagist-themes-install-ios-spyware-that-steals-crypto-wallet-seeds-mjl26lgwo)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"13 malicious Packagist themes install iOS spyware that steals crypto wallet seeds","url":"https://daily.dev/posts/13-malicious-packagist-themes-install-ios-spyware-that-steals-crypto-wallet-seeds-mjl26lgwo","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/13-malicious-packagist-themes-install-ios-spyware-that-steals-crypto-wallet-seeds-mjl26lgwo"},"datePublished":"2026-08-31T16:40:23.930Z","dateModified":"2026-08-31T16:41:04.230Z","description":"Socket's Threat Research Team uncovered 13 malicious Composer/Packagist theme packages, spread across five vendor namespaces, that trojanize front-end assets...","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/13-malicious-packagist-themes-install-ios-spyware-that-steals-crypto-wallet-seeds-mjl26lgwo","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,ios,php,crypto,malware","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"13 malicious Packagist themes install iOS spyware that steals crypto wallet seeds"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/13-malicious-packagist-themes-install-ios-spyware-that-steals-crypto-wallet-seeds-mjl26lgwo#faq","mainEntity":[{"@type":"Question","name":"Which iOS versions are vulnerable to the CVE-2025-31277 WebKit kernel escape used in the Packagist spyware campaign?","acceptedAnswer":{"@type":"Answer","text":"Older iPhones from the XS through the 16 running iOS 18.4 through 18.6.x remain exposed. Apple patched the underlying kernel escape, which chains CVE-2025-31277, CVE-2025-43529, and a CVE-2026-43655 variant, in iOS/macOS 26.1. Devices already updated to iOS 26.2 or 18.7.3 and above are not affected by this exploit chain. Developers tracking iOS security patches can follow CVE disclosures like this one on daily.dev."}},{"@type":"Question","name":"What crypto wallets are targeted by the spyware distributed through malicious Packagist theme packages?","acceptedAnswer":{"@type":"Answer","text":"The spyware specifically harvests seed phrases and mnemonics from Bitget, Phantom, Trust Wallet, OKX, and other crypto wallet apps, alongside keychain data, SMS messages, photos, contacts, and location history. It gets installed on unpatched iPhones after a WebKit-to-kernel escape triggered by trojanized JavaScript embedded in Composer theme packages for OphimCMS and KKPhim sites. Anyone building on crypto wallet integrations can track supply chain threats like this via daily.dev."}},{"@type":"Question","name":"How do I check if my Composer/Packagist project uses a malicious OphimCMS or KKPhim theme package?","acceptedAnswer":{"@type":"Answer","text":"Audit installed themes against the five malicious vendor namespaces identified by Socket's Threat Research Team, spanning 13 packages that trojanize front-end assets for Vietnamese streaming sites built on OphimCMS and KKPhim, both Laravel-based PHP CMSes. Remove any matching packages, rotate credentials, and update any iPhones exposed to the linked WebKit kernel exploit chain. PHP developers auditing dependencies for supply chain risks can follow reports like this on daily.dev."}}]}
```

