Incident
Published 2026-08-31
Verified 2026-09-19

Socket: 13 malicious Packagist themes push iOS WebKit-to-kernel spyware and wallet theft

Socket's 31 August 2026 research describes 13 malicious Composer theme packages on Packagist across five vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms) that inject JavaScript into Vietnamese movie and comic streaming sites. On mobile visitors the code runs gambling and ad-fraud redirects; on unpatched iPhones it loads a FUNNULL-hosted WebKit-to-kernel exploit chain. Socket says the renderer stages weaponise CVE-2025-31277 and CVE-2025-43529 (both on CISA KEV), then escape to the kernel; Apple told Socket the kernel escape was already fixed in iOS and macOS 26.1. A 12 August 2026 redeployment added keychain theft of crypto-wallet seeds and mnemonics for Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet and OKX, targeting iOS 18.4 through 18.6.x. Site operators should remove themes from those namespaces, rotate credentials, and audit shipped scripts; keep iPhones current past the listed builds.

Product
Packagist Composer themes (OphimCMS/KKPhim forks); iOS Safari/WebKit
Versions
iOS exploit tables cover 18.4–18.6.x; kernel escape fixed in iOS/macOS 26.1 per Apple to Socket; WebKit CVEs patched in later 18.7.3 / 26.2 builds per Socket
Exploited in Australia?
unknown
Patch to
Remove listed Packagist themes; update iOS past 18.6.x; block Socket IoCs

Primary: Socket (31 Aug 2026) · CVE: CVE-2025-31277, CVE-2025-43529 · The Hacker News (1 Sep 2026)

tech supply chain