Hackers are using booby-trapped website themes to turn visits from iPhone users into a route for spyware and cryptocurrency theft.

The campaign hides harmful code inside themes used by Vietnamese movie and comic streaming websites, exposing visitors without warning.

The poisoned themes are installed through Composer, a tool developers use to add website components. Once a site operator installs one, the code is delivered to every visitor.

Mobile users may be pushed toward gambling pages, while selected iPhone visitors face a far more serious chain. Because the script is served through a legitimate-looking page, victims may mistake the site for a normal streaming service.

Socket.dev said in a report shared with Cyber Security News (CSN) that it found 13 malicious theme packages across five namespaces.

The findings expand an earlier investigation and show how a compromised front-end theme can become a silent delivery channel for attacks against a site’s audience.

A trojanized Composer theme (Source – Socket.dev)

The campaign affects site operators. A successful infection can expose private device data and wallet recovery material, while the affected site operator may not know malicious scripts were included in the theme. The case also echoes how a popular npm package compromise can turn trusted software updates into an attack path.

Hackers Use Malicious Website Themes

The altered themes keep expected files, but attackers added JavaScript loaders to them. These loaders check the visitor’s device and referral source. Desktop browsers, automated scanners, and people arriving directly are ignored, limiting detection.

For mobile visitors, one branch injects advertising and sends browsers through a gambling redirect chain. For iPhone users who meet the campaign’s checks, a separate loader fetches more code from attacker-controlled infrastructure.

It then uses a hidden page to identify the installed iOS version and select an exploit designed for it. The research says the web attack targets two known WebKit flaws, CVE-2025-31277 and CVE-2025-43529, before moving from the browser toward deeper device access.

Apple had already fixed the kernel escape referenced by the researchers, and the affected WebKit entry points are public and patched. Readers can see why prompt patching matters in coverage of Apple WebKit zero-day flaws.

The payload configuration carries a hardcoded AES key (Source - Socket.dev)
The payload configuration carries a hardcoded AES key (Source – Socket.dev)

The chain was built for iPhones from the XS generation through the iPhone 16 family that remain on older releases.

According to the report, devices updated to iOS 18.7.3 on the iOS 18 line, or iOS 26.2 and later, are not exposed to the known stages. That means the operation relies on delayed updates rather than breaking current protections.

Spyware Targets Wallet Recovery Data

After gaining the necessary access, the spyware collects highly personal information, including keychain databases, Wi-Fi passwords, text messages, contacts, photos, browser cookies, call history, location records, and account data.

It encrypts the collected material and sends it to a changing set of command-and-control servers. A redeployed version observed in August added a focused wallet-theft capability.

It searches the iPhone keychain for seed phrases and mnemonic information from cryptocurrency wallets. Those recovery words can give criminals control of funds, making the intrusion more damaging than a conventional data-stealing incident.

The attackers refreshed filenames and staging components while older files remained reachable, complicating detection and takedowns.

This pattern resembles other package ecosystem threats, including credential-stealing dependency attacks, where code that appears useful can quietly collect valuable secrets after installation.

Website operators using the affected content management systems should remove untrusted themes, review their front-end scripts, rotate credentials handled on the host, and inspect network activity for the indicators below.

Developers should pin and review Composer dependencies, including themes and assets, because browser-side files execute in visitors’ sessions just as surely as server code.

Security teams should block the listed network indicators and look for suspicious page loaders, hidden iframes, and unusual browser requests.

They should also prioritize iPhone updates for devices still on older versions. The campaign is a reminder that software supply chain attacks can harm not only developers, but also every person who visits an affected website.

Indicators of compromise (IoCs):-

Type Indicator Description
Malicious Packagist package vsmov/theme-dy Trojanized Composer theme associated with the campaign
Malicious Packagist package vsmov/theme-rrdyw Trojanized Composer theme associated with the campaign
Malicious Packagist package vsmov/theme-motchill Trojanized Composer theme associated with the campaign
Malicious Packagist package vsmov/theme-vsmov Trojanized Composer theme associated with the campaign
Malicious Packagist package vsphim/theme-heovl Trojanized Composer theme associated with the campaign
Malicious Packagist package vsphim/theme-thempho Trojanized Composer theme associated with the campaign
Malicious Packagist package haiau009/kkphim-legend Trojanized Composer theme associated with the campaign
Malicious Packagist package haiau009/kkphim-motchill Trojanized Composer theme associated with the campaign
Malicious Packagist package chilltvcms/theme-legend Trojanized Composer theme associated with the campaign
Malicious Packagist package ophimcms/theme-dy Trojanized Composer theme associated with the campaign
Malicious Packagist package ophimcms/theme-motchill Trojanized Composer theme associated with the campaign
Malicious Packagist package ophimcms/theme-pcc Trojanized Composer theme associated with the campaign
Malicious Packagist package ophimcms/theme-rrdyw Trojanized Composer theme associated with the campaign
Threat actor handle vsmov Packagist vendor namespace
Threat actor handle vsphim Packagist vendor namespace and GitHub source account
Threat actor handle haiau009 Packagist vendor namespace
Threat actor handle chilltvcms Packagist vendor namespace
Threat actor handle ophimcms Packagist vendor namespace
Email address clemenciajohn74@gmail[.]com Committer email linked to the theme activity
Email address dev.cuongnguyen@gmail[.]com Committer email linked to the theme activity
Email address nguyenhai.tran.009@gmail[.]com Committer email linked to the theme activity
Email address xuxuthoi01@gmail[.]com Committer email linked to the theme activity
Email address tuwibu2021@gmail[.]com Committer email linked to the theme activity
Delivery URL union[.]macoms[.]la/jquery.min-3.6.8.js Second-stage JavaScript loader
Domain cdn[.]data-2920[.]com Exploit-delivery infrastructure
Domain cdn[.]data-2919[.]com Exploit-delivery infrastructure
Domain www[.]cloudfareintcdn[.]com Cloudflare-impersonating exploit infrastructure
Domain yunray[.]ai CNAME-cloaking infrastructure
Domain cdn1[.]ai DNS and control-plane infrastructure
Domain nqsaaskw[.]com Control-plane infrastructure
Domain abfedgecanme[.]com Campaign front infrastructure
Domain abfdns[.]com Name server associated with campaign infrastructure
Domain galedns[.]com Name server associated with campaign infrastructure
Exfiltration C2 www[.]0liwevrhxdc3s2xk00[.]com Data-exfiltration command-and-control host
Exfiltration C2 www[.]39rwcybep-20pwozhvdrzzy[.]net Data-exfiltration command-and-control host
Exfiltration C2 www[.]5wg3w278e3oamlohmcinrkh[.]live Data-exfiltration command-and-control host
Exfiltration C2 www[.]dlosdekr1u18msmov51[.]net Data-exfiltration command-and-control host
Exfiltration C2 www[.]ex0x40vmi8qyccxq[.]net Data-exfiltration command-and-control host
Exfiltration C2 www[.]ioa7xqmhiz26fv5e[.]info Data-exfiltration command-and-control host
Exfiltration C2 www[.]isbo31w1o7xk3fztvmgpbv[.]app Data-exfiltration command-and-control host
Exfiltration C2 www[.]jhflt6l0dwminsl494836rb[.]org Data-exfiltration command-and-control host
Exfiltration C2 www[.]kp2-3ur6pe4r8i2hj5[.]com Data-exfiltration command-and-control host
Exfiltration C2 www[.]ljot1cem6jhzfu53yb9aj3h[.]app Data-exfiltration command-and-control host
Exfiltration C2 www[.]ncalb1rzb2rq5-3zdx1[.]app Data-exfiltration command-and-control host
Exfiltration C2 www[.]ov86ayb0fe4ep2b92-645o[.]com Data-exfiltration command-and-control host
Exfiltration C2 www[.]qdh71-y6j7vxgw046v4cvgga[.]live Data-exfiltration command-and-control host
Exfiltration C2 www[.]sx3cjniwo1bmtqs0vlj-va2f[.]app Data-exfiltration command-and-control host
Exfiltration C2 www[.]sx8vuz4smtdol7pg[.]com Data-exfiltration command-and-control host
Exfiltration C2 www[.]t9ffxu6zhf915fadjv1[.]app Data-exfiltration command-and-control host
Exfiltration C2 www[.]vutjsf0sd9sdqt2rkzvgzv9a[.]org Data-exfiltration command-and-control host
Exfiltration C2 www[.]w4iunvbdvjof39q-3[.]net Data-exfiltration command-and-control host
Exfiltration C2 www[.]xtpj2bzxip6iq7n3bnz[.]info Data-exfiltration command-and-control host
Exfiltration C2 www[.]zfu4n4kxgmx32hsqg[.]cc Data-exfiltration command-and-control host
IP address and port 23[.]225[.]52[.]67:4466 Gambling and ad-fraud redirect infrastructure
IP address and port 23[.]225[.]48[.]20:4466 Gambling and ad-fraud redirect infrastructure
Domain im[.]ue8im[.]com Gambling advertisement image host
Domain and port xl0ph4qz[.]vip:7740 Gambling landing-page infrastructure
Domain cre-ads[.]com Advertising-related indicator
File and SHA-256 start-view.html / 60b6771958cb7e553994ba6752f108575ba70e02d24affb51d8936a17eb0bf5e Hidden iOS-version detection and exploit-launch page
File and SHA-256 a4tt4g37f36gdd7q7kdc.js / d9530e8cd79ac7b3d02b04e05426653afca7075fcf7424eec4d59c6e95745933 Renderer loader with CVE annotations
File and SHA-256 a84snnb6pknt3aflt01r.js / 92c7d246d2c163c076f783dcc19f87f5b9b9ac301b106b87a7aaea9346ce0052 iOS 18.4 to 18.5 remote-code-execution stage
File and SHA-256 921w48jmeqvt3ygn0wwx.js / f2fdfddbc436acc24a654092f5205b2c5bd3208b126b2c2754ac63e7aea22298 Kernel-escape stage
File and SHA-256 4ap5xpu18z70wwslqybu.js / 9d6b58886189c0e23f706c32d3d8dda97b0b6d927ece6de07270813f070295b5 Spyware payload
File and SHA-256 qljbd9a1h4a83gw8lxcj.js / de539a63cbe27bbd4a7db30fc796cd6dc5309c02ef5e60a3c5cf0835e5601283 iOS 18.6 and later worker
Redeployed file 98jgbibyeep2qfkvcq.html Redeployed orchestrator file observed on August 12, 2026
Redeployed file pf2zdl2b4i4cxggjg9s7.js Redeployed kernel-stage file observed on August 12, 2026
Redeployed file sejpbqlu090u7lz0z6ax.js Redeployed spyware-payload file observed on August 12, 2026
Cryptographic key 9_X1M=<;5 Hardcoded AES key in the crypto-wallet spyware configuration
Channel identifier 22c75b2ee026dbbf7001cfdc2bb47855 Hardcoded payload channel identifier

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.