13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds
13 malicious Packagist themes (vsmov, vsphim, haiau009, chilltvcms, ophimcms) inject JavaScript into Vietnamese streaming sites that serves a WebKit-to-kernel exploit chain to unpatched iPhone visitors. The chain uses CVE-2025-31277 and CVE-2025-43529 for initial execution, pivots through the GPU process, and escapes the sandbox via AppleM2ScalerCSCDriver to deploy spyware. The spyware exfiltrates keychain data, device databases, and cryptocurrency wallet seeds over HTTPS to FUNNULL infrastructure.
- cveCVE-2025-31277WebKit vulnerability exploited for client-side code execution on iOS 18.4 to 18.5.
- cveCVE-2025-43529WebKit vulnerability exploited for client-side code execution on iOS 18.6 and later.
- cveCVE-2026-43655Use-after-free in AppleM2ScalerCSCDriver fixed in iOS 26.5; the exploit chain uses a related but distinct primitive on the same driver surface.
- domainabfdns[.]comName server for abfedgecanme.com.
- domainabfedgecanme[.]comNewer front domain for FUNNULL campaign hosts.
- domaincdn1[.]aiName server infrastructure for FUNNULL front domains.
- domaincdn[.]data-2919[.]comStage 2 exploit host infrastructure.
- domaincdn[.]data-2920[.]comStage 2 exploit host serving app.vue.js which redirects to the WebKit exploit chain.
- domaincre-ads[.]comGambling and ad-fraud infrastructure domain.
- domaingaledns[.]comName server for abfedgecanme.com.
- domainim[.]ue8im[.]comGambling and ad-fraud host serving ad images.
- domainlsmzt[.]ccDomain resolving for im.ue8im.com.
- domainnqsaaskw[.]comControl plane domain for union.macoms.la.
- domainunion[.]macoms[.]laDomain hosting the second-stage loader jquery.min-3.6.8.js pulled by the injected theme code.
- domainv7[.]kkphimplayer7[.]comCampaign host fronted by abfedgecanme.com.
- domainwww[.]0liwevrhxdc3s2xk00[.]comExfiltration C2 domain.
- domainwww[.]39rwcybep-20pwozhvdrzzy[.]netExfiltration C2 domain.
- domainwww[.]5wg3w278e3oamlohmcinrkh[.]liveExfiltration C2 domain.
- domainwww[.]cloudfareintcdn[.]comCloudflare-impersonating domain serving in-static.js which injects the hidden iframe for the WebKit exploit.
- domainwww[.]dlosdekr1u18msmov51[.]netExfiltration C2 domain.
- domainwww[.]ex0x40vmi8qyccxq[.]netExfiltration C2 domain.
- domainwww[.]ioa7xqmhiz26fv5e[.]infoExfiltration C2 domain.
- domainwww[.]isbo31w1o7xk3fztvmgpbv[.]appExfiltration C2 domain.
- domainwww[.]jhflt6l0dwminsl494836rb[.]orgExfiltration C2 domain.
- domainwww[.]kp2-3ur6pe4r8i2hj5[.]comExfiltration C2 domain.
- domainwww[.]ljot1cem6jhzfu53yb9aj3h[.]appExfiltration C2 domain.
- domainwww[.]ncalb1rzb2rq5-3zdx1[.]appExfiltration C2 domain.
- domainwww[.]ov86ayb0fe4ep2b92-645o[.]comExfiltration C2 domain.
- domainwww[.]qdh71-y6j7vxgw046v4cvgga[.]liveExfiltration C2 domain.
- domainwww[.]sx3cjniwo1bmtqs0vlj-va2f[.]appExfiltration C2 domain.
- domainwww[.]sx8vuz4smtdol7pg[.]comExfiltration C2 domain.
- domainwww[.]t9ffxu6zhf915fadjv1[.]appExfiltration C2 domain.
- domainwww[.]vutjsf0sd9sdqt2rkzvgzv9a[.]orgExfiltration C2 domain.
- domainwww[.]w4iunvbdvjof39q-3[.]netExfiltration C2 domain.
- domainwww[.]xtpj2bzxip6iq7n3bnz[.]infoExfiltration C2 domain.
- domainwww[.]zfu4n4kxgmx32hsqg[.]ccExfiltration C2 domain.
- domainxemphimlau[.]comDomain used for devtools-detection redirect in anti-analysis code.
- domainxl0ph4qz[.]vipGambling landing page domain on port 7740.
- domainyunray[.]aiCNAME-cloak destination for FUNNULL infrastructure, used by exploit and exfiltration domains.
- emaildev[.]cuongnguyen[@]gmail[.]comCommitter email linked to the malicious Vietnamese theme operators on Packagist.
- filename4ap5xpu18z70wwslqybu.jsSpyware payload file responsible for data and crypto wallet theft.
- filenamea4tt4g37f36gdd7q7kdc.jsRenderer loader file containing CVE annotations.
- filenameindexbottom.jsFile containing the mobile gambling and ad-fraud banner injection.
- filenamephimv2.3.jsFile containing anti-analysis redirects and debug blocking.
- filenamestart-view.htmlExploit stage file loaded in a hidden iframe that determines iOS version.
- ip103[.]231[.]15[.]199IP address resolving from cdn.data-2920.com CNAME chain.
- ip103[.]246[.]244[.]56IP address resolving from www.0liwevrhxdc3s2xk00.com exfiltration domain.
- ip202[.]181[.]25[.]3IP address resolving from www.cloudfareintcdn.com CNAME chain.
- ip202[.]181[.]25[.]81IP address resolving from union.macoms.la CNAME chain.
- ip23[.]225[.]48[.]20Gambling and ad-fraud redirect host serving vip/index.php.
- ip23[.]225[.]52[.]67IP address for the gambling and ad-fraud redirect host serving vip344.html.
- sha25660b6771958cb7e553994ba6752f108575ba70e02d24affb51d8936a17eb0bf5eHash of start-view.html which reads iOS version and loads the WebKit exploit.
- sha25692c7d246d2c163c076f783dcc19f87f5b9b9ac301b106b87a7aaea9346ce0052Hash of a84snnb6pknt3aflt01r.js, the iOS 18.4 to 18.5 RCE payload.
- sha2569d6b58886189c0e23f706c32d3d8dda97b0b6d927ece6de07270813f070295b5SHA256 hash of the spyware payload file 4ap5xpu18z70wwslqybu.js which steals keychain and crypto wallet data.
- sha256d9530e8cd79ac7b3d02b04e05426653afca7075fcf7424eec4d59c6e95745933SHA256 hash of the renderer loader a4tt4g37f36gdd7q7kdc.js which contains CVE annotations and initial exploit logic.
- sha256de539a63cbe27bbd4a7db30fc796cd6dc5309c02ef5e60a3c5cf0835e5601283Hash of qljbd9a1h4a83gw8lxcj.js, the iOS 18.6+ worker payload.
- sha256f2fdfddbc436acc24a654092f5205b2c5bd3208b126b2c2754ac63e7aea22298Hash of 921w48jmeqvt3ygn0wwx.js, the kernel escape payload.
- urlhxxps://23[.]225[.]48[.]20:4466/vip/index[.]phpGambling redirect URL that sets a session cookie and forwards to .vip landing pages.
- urlhxxps://23[.]225[.]52[.]67:4466/vip344[.]htmlGambling redirect URL targeted by the mobile ad-fraud banner.
- urlhxxps://im[.]ue8im[.]com/wg-2023440066/640-100-1[.]gifAd-fraud image URL loaded from the malicious redirect host im.ue8im.com.
- urlhxxps://union[.]macoms[.]la/jquery[.]min-3[.]6[.]8[.]jsSecond-stage loader URL fetched by the injected theme JavaScript.
- urlhxxps://www[.]cloudfareintcdn[.]com/in-static[.]jsURL for the script that injects a hidden iframe to start-view.html to trigger the iOS version-specific WebKit exploit.
- urlhxxps://www[.]cloudfareintcdn[.]com/wd-status[.]htmlURL beacons used by the worker to report exploitation progress.
Detection / Hunteropenrouter
What Happened
Thirteen fake website themes for a popular Vietnamese content management system were found to contain hidden malicious code. When someone visits a site using these themes on an older, unpatched iPhone, the code exploits security flaws in the iPhone's web browser to install spyware. This spyware steals sensitive information like saved passwords, photos, and the recovery phrases for cryptocurrency wallets. The attacks come from a group using infrastructure run by FUNNULL, a company that was recently sanctioned for helping cybercriminals. To stay safe, iPhone users should update their devices to the latest software version, and website operators should check their installed themes and remove any from the listed vendors.
Key Takeaways
- 13 malicious Packagist theme packages inject JavaScript into Vietnamese movie and comic streaming sites to serve a WebKit-to-kernel exploit chain targeting unpatched iPhones.
- The exploit chain leverages CVE-2025-31277 and CVE-2025-43529 in WebKit for initial code execution, pivots to the GPU process, and escapes the kernel sandbox via AppleM2ScalerCSCDriver.
- The spyware payload exfiltrates keychain databases, Wi-Fi passwords, SMS, photos, and cryptocurrency wallet seeds from Bitget, OKX, Phantom, Trust Wallet, and others.
- Threat infrastructure is hosted on FUNNULL (Triad Nexus), a provider sanctioned by OFAC, with exfiltration domains registered in a single bulk burst.
- Apple confirmed the kernel escape was addressed in iOS and macOS 26.1, and the WebKit entry points are listed in CISA's Known Exploited Vulnerabilities catalog.
Affected Systems
- iOS 18.4 through 18.6.x
- iPhone XS through iPhone 16 family
- macOS (kernel escape fixed in 26.1)
- OphimCMS
- KKPhim
Vulnerabilities (CVEs)
| CVE | Product | Severity | Description |
|---|---|---|---|
| CVE-2025-31277 | Apple WebKit | High | WebKit vulnerability exploited for client-side code execution on iOS 18.4 to 18.5. |
| CVE-2025-43529 | Apple WebKit | High | WebKit vulnerability exploited for client-side code execution on iOS 18.6 and later. |
| CVE-2026-43655 | AppleM2ScalerCSCDriver | High | Use-after-free in AppleM2ScalerCSCDriver fixed in iOS 26.5; the exploit chain uses a related but distinct primitive on the same driver surface. |
Attack Chain
- Initial Access: User visits a Vietnamese movie or comic streaming site that installed a malicious Packagist theme.
- Execution: Injected JavaScript in the theme loads a second stage from union.macoms.la which then pulls exploit code from cdn.data-2920.com.
- Exploitation: A hidden iframe loads start-view.html which triggers WebKit vulnerabilities (CVE-2025-31277 or CVE-2025-43529) based on the visitor's iOS version.
- Privilege Escalation: The renderer pivots to the GPU process using IOSurface and mach messaging, then escapes the sandbox via AppleM2ScalerCSCDriver to gain kernel read/write capabilities.
- Exfiltration: Spyware payload collects keychain, Wi-Fi passwords, SMS, photos, and crypto wallet seeds, encrypts them with AES, and uploads to rotating C2 domains.
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
The article provides IOC indicators and behavioral descriptions but does not provide specific detection rule content.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Low | The exploit chain targets iOS devices via a drive-by web compromise. Traditional EDR agents are typically not present or have limited visibility on iOS devices, and the exploitation occurs inside the WebKit renderer and kernel space. |
| Network Visibility | High | The attack chain makes multiple HTTP/HTTPS requests to external domains for stage loading and exfiltration. Network monitoring can identify connections to the listed C2 domains and IPs. |
| Detection Difficulty | Moderate | Defenders can block and hunt for the listed network indicators. However, the exploit itself relies on n-day vulnerabilities in WebKit and the kernel that may not generate alerts on unpatched devices without specific endpoint telemetry. |
Required Log Sources
- DNS query logs
- Proxy logs
- Firewall logs
- Web server access logs (for site operators)
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Look for network connections to domains that CNAME-cloak into yunray.ai or cdn1.ai, as these indicate FUNNULL infrastructure usage. | DNS resolution logs, passive DNS data, proxy logs | Command and Control | Low, as these specific infrastructure domains are attributed to threat activity. |
| Hunt for web traffic containing requests to /upload on the rotating exfiltration domains, which indicates spyware payload delivery. | Proxy logs, firewall logs | Exfiltration | Low, as these are randomly generated domains specifically used for C2. |
| Identify Composer or Packagist dependencies resolving to the vendors vsmov, vsphim, haiau009, chilltvcms, or ophimcms in your environment. | Package manager logs, CI/CD pipeline logs, software inventory | Initial Access | Low, as these vendors are confirmed malicious. |
| Look for outbound connections to port 4466 or 7740 associated with gambling redirect hosts, which may indicate the ad-fraud branch of the campaign. | Firewall logs, network flow data | Execution | Medium, as these ports could theoretically be used by other services, but the combination with the listed IPs is suspicious. |
Control Gaps
- Lack of endpoint visibility on iOS devices limits detection of kernel and WebKit exploitation.
- Unpatched iOS devices remain vulnerable to the n-day exploit chain.
- Reliance on network-level blocking may miss encrypted C2 traffic if domains rotate faster than blocklists update.
Key Behavioral Indicators
- Network connections to union.macoms.la
- Network connections to cdn.data-2920.com or cdn.data-2919.com
- Network connections to www.cloudfareintcdn.com
- HTTP requests to /upload on rotating .com/.net/.live/.info/.app/.org/.cc exfiltration domains
- Presence of session storage keys rce_locked and uid
- Beacons to cloudfareintcdn.com/wd-status.html
False Positive Assessment
Low
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting.
- Block the network indicators and exfiltration domains listed in the article at your firewall and proxy.
- Audit installed Composer dependencies for packages from the vendors vsmov, vsphim, haiau009, chilltvcms, or ophimcms, and remove them if found.
- Prioritize updating any iPhones currently running iOS 18.6.x or earlier to iOS 26.2 or later to patch the WebKit entry points.
Infrastructure Hardening
- Consider pinning and reviewing Composer dependencies before deployment.
- Evaluate whether your web properties use OphimCMS or KKPhim and ensure no malicious themes are installed.
- If applicable, implement DNS filtering to block connections to known FUNNULL infrastructure such as yunray.ai and cdn1.ai.
User Protection
- Ensure all managed iOS devices are updated to iOS 26.2 or later.
- If your MDM solution supports it, consider enforcing minimum OS versions for corporate devices.
- Advise users to avoid visiting untrusted Vietnamese movie and comic streaming sites on unpatched devices.
Security Awareness
- Communicate the risk of supply chain compromise to development teams, emphasizing that front-end assets shipped inside packages execute code in users' browsers.
- Remind users that keeping mobile devices updated is critical for mitigating n-day exploit risks.
MITRE ATT&CK Mapping
Resource Development
Initial Access
Execution
Privilege Escalation
Stealth
Credential Access
Command and Control
Exfiltration
Additional IOCs
- Ips:
23[.]225[.]48[.]20- Gambling and ad-fraud redirect host serving vip/index.php.202[.]181[.]25[.]3- IP address resolving from www.cloudfareintcdn.com CNAME chain.103[.]231[.]15[.]199- IP address resolving from cdn.data-2920.com CNAME chain.103[.]246[.]244[.]56- IP address resolving from www.0liwevrhxdc3s2xk00.com exfiltration domain.202[.]181[.]25[.]81- IP address resolving from union.macoms.la CNAME chain.
- Domains:
cdn[.]data-2919[.]com- Stage 2 exploit host infrastructure.nqsaaskw[.]com- Control plane domain for union.macoms.la.cdn1[.]ai- Name server infrastructure for FUNNULL front domains.abfedgecanme[.]com- Newer front domain for FUNNULL campaign hosts.abfdns[.]com- Name server for abfedgecanme.com.galedns[.]com- Name server for abfedgecanme.com.im[.]ue8im[.]com- Gambling and ad-fraud host serving ad images.lsmzt[.]cc- Domain resolving for im.ue8im.com.xemphimlau[.]com- Domain used for devtools-detection redirect in anti-analysis code.cre-ads[.]com- Gambling and ad-fraud infrastructure domain.xl0ph4qz[.]vip- Gambling landing page domain on port 7740.v7[.]kkphimplayer7[.]com- Campaign host fronted by abfedgecanme.com.www[.]0liwevrhxdc3s2xk00[.]com- Exfiltration C2 domain.www[.]39rwcybep-20pwozhvdrzzy[.]net- Exfiltration C2 domain.www[.]5wg3w278e3oamlohmcinrkh[.]live- Exfiltration C2 domain.www[.]dlosdekr1u18msmov51[.]net- Exfiltration C2 domain.www[.]ex0x40vmi8qyccxq[.]net- Exfiltration C2 domain.www[.]ioa7xqmhiz26fv5e[.]info- Exfiltration C2 domain.www[.]isbo31w1o7xk3fztvmgpbv[.]app- Exfiltration C2 domain.www[.]jhflt6l0dwminsl494836rb[.]org- Exfiltration C2 domain.www[.]kp2-3ur6pe4r8i2hj5[.]com- Exfiltration C2 domain.www[.]ljot1cem6jhzfu53yb9aj3h[.]app- Exfiltration C2 domain.www[.]ncalb1rzb2rq5-3zdx1[.]app- Exfiltration C2 domain.www[.]ov86ayb0fe4ep2b92-645o[.]com- Exfiltration C2 domain.www[.]qdh71-y6j7vxgw046v4cvgga[.]live- Exfiltration C2 domain.www[.]sx3cjniwo1bmtqs0vlj-va2f[.]app- Exfiltration C2 domain.www[.]sx8vuz4smtdol7pg[.]com- Exfiltration C2 domain.www[.]t9ffxu6zhf915fadjv1[.]app- Exfiltration C2 domain.www[.]vutjsf0sd9sdqt2rkzvgzv9a[.]org- Exfiltration C2 domain.www[.]w4iunvbdvjof39q-3[.]net- Exfiltration C2 domain.www[.]xtpj2bzxip6iq7n3bnz[.]info- Exfiltration C2 domain.www[.]zfu4n4kxgmx32hsqg[.]cc- Exfiltration C2 domain.
- Urls:
hxxps://23[.]225[.]52[.]67:4466/vip344.html- Gambling redirect URL targeted by the mobile ad-fraud banner.hxxps://23[.]225[.]48[.]20:4466/vip/index.php- Gambling redirect URL that sets a session cookie and forwards to .vip landing pages.hxxps://union[.]macoms[.]la/jquery.min-3.6.8.js- Second-stage loader URL fetched by the injected theme JavaScript.hxxps://www[.]cloudfareintcdn[.]com/wd-status.html- URL beacons used by the worker to report exploitation progress.
- File Hashes:
60b6771958cb7e553994ba6752f108575ba70e02d24affb51d8936a17eb0bf5e(SHA256) - Hash of start-view.html which reads iOS version and loads the WebKit exploit.92c7d246d2c163c076f783dcc19f87f5b9b9ac301b106b87a7aaea9346ce0052(SHA256) - Hash of a84snnb6pknt3aflt01r.js, the iOS 18.4 to 18.5 RCE payload.f2fdfddbc436acc24a654092f5205b2c5bd3208b126b2c2754ac63e7aea22298(SHA256) - Hash of 921w48jmeqvt3ygn0wwx.js, the kernel escape payload.de539a63cbe27bbd4a7db30fc796cd6dc5309c02ef5e60a3c5cf0835e5601283(SHA256) - Hash of qljbd9a1h4a83gw8lxcj.js, the iOS 18.6+ worker payload.
- File Paths:
start-view.html- Exploit stage file loaded in a hidden iframe that determines iOS version.a4tt4g37f36gdd7q7kdc.js- Renderer loader file containing CVE annotations.4ap5xpu18z70wwslqybu.js- Spyware payload file responsible for data and crypto wallet theft.phimv2.3.js- File containing anti-analysis redirects and debug blocking.indexbottom.js- File containing the mobile gambling and ad-fraud banner injection.
- Command Lines:
- Purpose: Package installation for Vietnamese movie streaming CMS | Tools:
composer| Stage: Initial Access |composer require <vendor>/<package>
- Purpose: Package installation for Vietnamese movie streaming CMS | Tools:
- Other:
9_X1<yW,DC>M=<;5- Hardcoded AES key used by the spyware payload to encrypt exfiltrated data.22c75b2ee026dbbf7001cfdc2bb47855- Per-build channel identifier used by the spyware payload.[email protected]- Committer email linked to malicious theme operators.[email protected]- Committer email linked to malicious theme operators.[email protected]- Committer email linked to malicious theme operators.[email protected]- Committer email linked to malicious theme operators.