Socket: 13 malicious Packagist themes push iOS WebKit-to-kernel spyware and wallet theft
Socket's 31 August 2026 research describes 13 malicious Composer theme packages on Packagist across five vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms) that inject JavaScript into Vietnamese movie and comic streaming sites. On mobile visitors the code runs gambling and ad-fraud redirects; on unpatched iPhones it loads a FUNNULL-hosted WebKit-to-kernel exploit chain. Socket says the renderer stages weaponise CVE-2025-31277 and CVE-2025-43529 (both on CISA KEV), then escape to the kernel; Apple told Socket the kernel escape was already fixed in iOS and macOS 26.1. A 12 August 2026 redeployment added keychain theft of crypto-wallet seeds and mnemonics for Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet and OKX, targeting iOS 18.4 through 18.6.x. Site operators should remove themes from those namespaces, rotate credentials, and audit shipped scripts; keep iPhones current past the listed builds.
- Product
- Packagist Composer themes (OphimCMS/KKPhim forks); iOS Safari/WebKit
- Versions
- iOS exploit tables cover 18.4–18.6.x; kernel escape fixed in iOS/macOS 26.1 per Apple to Socket; WebKit CVEs patched in later 18.7.3 / 26.2 builds per Socket
- Exploited in Australia?
- unknown
- Patch to
- Remove listed Packagist themes; update iOS past 18.6.x; block Socket IoCs
Primary: Socket (31 Aug 2026) · CVE: CVE-2025-31277, CVE-2025-43529 · The Hacker News (1 Sep 2026)
