<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/6-malicious-packagist-themes-ship-trojanized-jquery-and-funn--bkmj35bje" -->

---
title: 6 Malicious Packagist Themes Ship Trojanized jQuery and...
description: Socket&#x27;s Threat Research Team discovered six malicious Composer packages on Packagist posing as OphimCMS themes for Vietnamese Laravel movie streaming sites....
canonical: https://daily.dev/posts/6-malicious-packagist-themes-ship-trojanized-jquery-and-funn--bkmj35bje
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: 6 Malicious Packagist Themes Ship Trojanized jQuery and FUNN... | daily.dev
og:description: Socket&#x27;s Threat Research Team discovered six malicious Composer packages on Packagist posing as OphimCMS themes for Vietnamese Laravel movie streaming sites....
og:url: https://daily.dev/posts/6-malicious-packagist-themes-ship-trojanized-jquery-and-funn--bkmj35bje
og:image: https://api.daily.dev/og/posts/bkMJ35bJe.png
og:image:alt: 6 Malicious Packagist Themes Ship Trojanized jQuery and FUNN...
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# 6 Malicious Packagist Themes Ship Trojanized jQuery and FUNN...

**[Socket](https://daily.dev/sources/socketdev)** · 12 min read · 0 upvotes · 0 comments

## Summary

Socket's Threat Research Team discovered six malicious Composer packages on Packagist posing as OphimCMS themes for Vietnamese Laravel movie streaming sites. The packages contain trojanized jQuery files that execute multiple attack chains: URL exfiltration to userstat[.]net via Caesar cipher-obfuscated C2 calls, FUNNULL-linked mobile redirects to gambling and adult content via union[.]macoms[.]la (using 3-layer obfuscation and multiple evasion checks), unauthorized ad injection, click hijacking, and anti-debugging measures. FUNNULL Technology Inc. is a Philippines-based CDN provider sanctioned by OFAC in May 2025 for facilitating over $200 million in crypto fraud. The payloads are embedded in bundled JS assets rather than PHP code, making them invisible to developers auditing only the PHP layer. The union[.]macoms[.]la payload was updated as recently as March 10, 2026, nearly ten months after sanctions. Total installs across the six packages reached approximately 2,750. Remediation steps include removing affected themes, auditing outbound network requests, and inspecting jQuery files for appended or inline injected code.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://socket.dev/blog/6-malicious-packagist-themes-ship-trojanized-jquery>

---

Tags: [#security](https://daily.dev/tags/security), [#javascript](https://daily.dev/tags/javascript), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/6-malicious-packagist-themes-ship-trojanized-jquery-and-funn--bkmj35bje)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"6 Malicious Packagist Themes Ship Trojanized jQuery and FUNN...","url":"https://daily.dev/posts/6-malicious-packagist-themes-ship-trojanized-jquery-and-funn--bkmj35bje","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/6-malicious-packagist-themes-ship-trojanized-jquery-and-funn--bkmj35bje"},"datePublished":"2026-03-12T15:46:15.387Z","dateModified":"2026-03-12T15:46:56.436Z","description":"Socket's Threat Research Team discovered six malicious Composer packages on Packagist posing as OphimCMS themes for Vietnamese Laravel movie streaming sites....","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/9c94a1b75ce0390e48b227be4da2c9fa?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/9c94a1b75ce0390e48b227be4da2c9fa?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Socket","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Socket","logo":"https://media.daily.dev/image/upload/s---oEn9czC--/f_auto/v1716187892/logos/socketdev","url":"https://daily.dev/sources/socketdev"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/6-malicious-packagist-themes-ship-trojanized-jquery-and-funn--bkmj35bje","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,javascript,malware","timeRequired":"PT12M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Socket","item":"https://daily.dev/sources/socketdev"},{"@type":"ListItem","position":3,"name":"6 Malicious Packagist Themes Ship Trojanized jQuery and FUNN..."}]}
```

