Hackers are using booby-trapped website themes to turn visits from iPhone users into a route for spyware and cryptocurrency theft.
The campaign hides harmful code inside themes used by Vietnamese movie and comic streaming websites, exposing visitors without warning.
The poisoned themes are installed through Composer, a tool developers use to add website components. Once a site operator installs one, the code is delivered to every visitor.
Mobile users may be pushed toward gambling pages, while selected iPhone visitors face a far more serious chain. Because the script is served through a legitimate-looking page, victims may mistake the site for a normal streaming service.
Socket.dev said in a report shared with Cyber Security News (CSN) that it found 13 malicious theme packages across five namespaces.
The findings expand an earlier investigation and show how a compromised front-end theme can become a silent delivery channel for attacks against a site’s audience.
The campaign affects site operators. A successful infection can expose private device data and wallet recovery material, while the affected site operator may not know malicious scripts were included in the theme. The case also echoes how a popular npm package compromise can turn trusted software updates into an attack path.
Hackers Use Malicious Website Themes
The altered themes keep expected files, but attackers added JavaScript loaders to them. These loaders check the visitor’s device and referral source. Desktop browsers, automated scanners, and people arriving directly are ignored, limiting detection.
For mobile visitors, one branch injects advertising and sends browsers through a gambling redirect chain. For iPhone users who meet the campaign’s checks, a separate loader fetches more code from attacker-controlled infrastructure.
It then uses a hidden page to identify the installed iOS version and select an exploit designed for it. The research says the web attack targets two known WebKit flaws, CVE-2025-31277 and CVE-2025-43529, before moving from the browser toward deeper device access.
Apple had already fixed the kernel escape referenced by the researchers, and the affected WebKit entry points are public and patched. Readers can see why prompt patching matters in coverage of Apple WebKit zero-day flaws.
.webp)
The chain was built for iPhones from the XS generation through the iPhone 16 family that remain on older releases.
According to the report, devices updated to iOS 18.7.3 on the iOS 18 line, or iOS 26.2 and later, are not exposed to the known stages. That means the operation relies on delayed updates rather than breaking current protections.
Spyware Targets Wallet Recovery Data
After gaining the necessary access, the spyware collects highly personal information, including keychain databases, Wi-Fi passwords, text messages, contacts, photos, browser cookies, call history, location records, and account data.
It encrypts the collected material and sends it to a changing set of command-and-control servers. A redeployed version observed in August added a focused wallet-theft capability.
It searches the iPhone keychain for seed phrases and mnemonic information from cryptocurrency wallets. Those recovery words can give criminals control of funds, making the intrusion more damaging than a conventional data-stealing incident.
The attackers refreshed filenames and staging components while older files remained reachable, complicating detection and takedowns.
This pattern resembles other package ecosystem threats, including credential-stealing dependency attacks, where code that appears useful can quietly collect valuable secrets after installation.
Website operators using the affected content management systems should remove untrusted themes, review their front-end scripts, rotate credentials handled on the host, and inspect network activity for the indicators below.
Developers should pin and review Composer dependencies, including themes and assets, because browser-side files execute in visitors’ sessions just as surely as server code.
Security teams should block the listed network indicators and look for suspicious page loaders, hidden iframes, and unusual browser requests.
They should also prioritize iPhone updates for devices still on older versions. The campaign is a reminder that software supply chain attacks can harm not only developers, but also every person who visits an affected website.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Malicious Packagist package | vsmov/theme-dy |
Trojanized Composer theme associated with the campaign |
| Malicious Packagist package | vsmov/theme-rrdyw |
Trojanized Composer theme associated with the campaign |
| Malicious Packagist package | vsmov/theme-motchill |
Trojanized Composer theme associated with the campaign |
| Malicious Packagist package | vsmov/theme-vsmov |
Trojanized Composer theme associated with the campaign |
| Malicious Packagist package | vsphim/theme-heovl |
Trojanized Composer theme associated with the campaign |
| Malicious Packagist package | vsphim/theme-thempho |
Trojanized Composer theme associated with the campaign |
| Malicious Packagist package | haiau009/kkphim-legend |
Trojanized Composer theme associated with the campaign |
| Malicious Packagist package | haiau009/kkphim-motchill |
Trojanized Composer theme associated with the campaign |
| Malicious Packagist package | chilltvcms/theme-legend |
Trojanized Composer theme associated with the campaign |
| Malicious Packagist package | ophimcms/theme-dy |
Trojanized Composer theme associated with the campaign |
| Malicious Packagist package | ophimcms/theme-motchill |
Trojanized Composer theme associated with the campaign |
| Malicious Packagist package | ophimcms/theme-pcc |
Trojanized Composer theme associated with the campaign |
| Malicious Packagist package | ophimcms/theme-rrdyw |
Trojanized Composer theme associated with the campaign |
| Threat actor handle | vsmov |
Packagist vendor namespace |
| Threat actor handle | vsphim |
Packagist vendor namespace and GitHub source account |
| Threat actor handle | haiau009 |
Packagist vendor namespace |
| Threat actor handle | chilltvcms |
Packagist vendor namespace |
| Threat actor handle | ophimcms |
Packagist vendor namespace |
| Email address | clemenciajohn74@gmail[.]com |
Committer email linked to the theme activity |
| Email address | dev.cuongnguyen@gmail[.]com |
Committer email linked to the theme activity |
| Email address | nguyenhai.tran.009@gmail[.]com |
Committer email linked to the theme activity |
| Email address | xuxuthoi01@gmail[.]com |
Committer email linked to the theme activity |
| Email address | tuwibu2021@gmail[.]com |
Committer email linked to the theme activity |
| Delivery URL | union[.]macoms[.]la/jquery.min-3.6.8.js |
Second-stage JavaScript loader |
| Domain | cdn[.]data-2920[.]com |
Exploit-delivery infrastructure |
| Domain | cdn[.]data-2919[.]com |
Exploit-delivery infrastructure |
| Domain | www[.]cloudfareintcdn[.]com |
Cloudflare-impersonating exploit infrastructure |
| Domain | yunray[.]ai |
CNAME-cloaking infrastructure |
| Domain | cdn1[.]ai |
DNS and control-plane infrastructure |
| Domain | nqsaaskw[.]com |
Control-plane infrastructure |
| Domain | abfedgecanme[.]com |
Campaign front infrastructure |
| Domain | abfdns[.]com |
Name server associated with campaign infrastructure |
| Domain | galedns[.]com |
Name server associated with campaign infrastructure |
| Exfiltration C2 | www[.]0liwevrhxdc3s2xk00[.]com |
Data-exfiltration command-and-control host |
| Exfiltration C2 | www[.]39rwcybep-20pwozhvdrzzy[.]net |
Data-exfiltration command-and-control host |
| Exfiltration C2 | www[.]5wg3w278e3oamlohmcinrkh[.]live |
Data-exfiltration command-and-control host |
| Exfiltration C2 | www[.]dlosdekr1u18msmov51[.]net |
Data-exfiltration command-and-control host |
| Exfiltration C2 | www[.]ex0x40vmi8qyccxq[.]net |
Data-exfiltration command-and-control host |
| Exfiltration C2 | www[.]ioa7xqmhiz26fv5e[.]info |
Data-exfiltration command-and-control host |
| Exfiltration C2 | www[.]isbo31w1o7xk3fztvmgpbv[.]app |
Data-exfiltration command-and-control host |
| Exfiltration C2 | www[.]jhflt6l0dwminsl494836rb[.]org |
Data-exfiltration command-and-control host |
| Exfiltration C2 | www[.]kp2-3ur6pe4r8i2hj5[.]com |
Data-exfiltration command-and-control host |
| Exfiltration C2 | www[.]ljot1cem6jhzfu53yb9aj3h[.]app |
Data-exfiltration command-and-control host |
| Exfiltration C2 | www[.]ncalb1rzb2rq5-3zdx1[.]app |
Data-exfiltration command-and-control host |
| Exfiltration C2 | www[.]ov86ayb0fe4ep2b92-645o[.]com |
Data-exfiltration command-and-control host |
| Exfiltration C2 | www[.]qdh71-y6j7vxgw046v4cvgga[.]live |
Data-exfiltration command-and-control host |
| Exfiltration C2 | www[.]sx3cjniwo1bmtqs0vlj-va2f[.]app |
Data-exfiltration command-and-control host |
| Exfiltration C2 | www[.]sx8vuz4smtdol7pg[.]com |
Data-exfiltration command-and-control host |
| Exfiltration C2 | www[.]t9ffxu6zhf915fadjv1[.]app |
Data-exfiltration command-and-control host |
| Exfiltration C2 | www[.]vutjsf0sd9sdqt2rkzvgzv9a[.]org |
Data-exfiltration command-and-control host |
| Exfiltration C2 | www[.]w4iunvbdvjof39q-3[.]net |
Data-exfiltration command-and-control host |
| Exfiltration C2 | www[.]xtpj2bzxip6iq7n3bnz[.]info |
Data-exfiltration command-and-control host |
| Exfiltration C2 | www[.]zfu4n4kxgmx32hsqg[.]cc |
Data-exfiltration command-and-control host |
| IP address and port | 23[.]225[.]52[.]67:4466 |
Gambling and ad-fraud redirect infrastructure |
| IP address and port | 23[.]225[.]48[.]20:4466 |
Gambling and ad-fraud redirect infrastructure |
| Domain | im[.]ue8im[.]com |
Gambling advertisement image host |
| Domain and port | xl0ph4qz[.]vip:7740 |
Gambling landing-page infrastructure |
| Domain | cre-ads[.]com |
Advertising-related indicator |
| File and SHA-256 | start-view.html / 60b6771958cb7e553994ba6752f108575ba70e02d24affb51d8936a17eb0bf5e |
Hidden iOS-version detection and exploit-launch page |
| File and SHA-256 | a4tt4g37f36gdd7q7kdc.js / d9530e8cd79ac7b3d02b04e05426653afca7075fcf7424eec4d59c6e95745933 |
Renderer loader with CVE annotations |
| File and SHA-256 | a84snnb6pknt3aflt01r.js / 92c7d246d2c163c076f783dcc19f87f5b9b9ac301b106b87a7aaea9346ce0052 |
iOS 18.4 to 18.5 remote-code-execution stage |
| File and SHA-256 | 921w48jmeqvt3ygn0wwx.js / f2fdfddbc436acc24a654092f5205b2c5bd3208b126b2c2754ac63e7aea22298 |
Kernel-escape stage |
| File and SHA-256 | 4ap5xpu18z70wwslqybu.js / 9d6b58886189c0e23f706c32d3d8dda97b0b6d927ece6de07270813f070295b5 |
Spyware payload |
| File and SHA-256 | qljbd9a1h4a83gw8lxcj.js / de539a63cbe27bbd4a7db30fc796cd6dc5309c02ef5e60a3c5cf0835e5601283 |
iOS 18.6 and later worker |
| Redeployed file | 98jgbibyeep2qfkvcq.html |
Redeployed orchestrator file observed on August 12, 2026 |
| Redeployed file | pf2zdl2b4i4cxggjg9s7.js |
Redeployed kernel-stage file observed on August 12, 2026 |
| Redeployed file | sejpbqlu090u7lz0z6ax.js |
Redeployed spyware-payload file observed on August 12, 2026 |
| Cryptographic key | 9_X1 |
Hardcoded AES key in the crypto-wallet spyware configuration |
| Channel identifier | 22c75b2ee026dbbf7001cfdc2bb47855 |
Hardcoded payload channel identifier |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.