At a Glance
- Malware family: FUNNULL-hosted iOS spyware
- Threat actor: Suspected Vietnamese-operated group
- Targets or victims: Mobile visitors to Vietnamese streaming sites
- Delivery vector: Trojanized Composer themes
- Key capabilities: WebKit-to-kernel exploit, crypto wallet theft, ad-fraud
- Source: Socket Threat Research Team
TL;DR
Thirteen malicious Composer packages inject JavaScript into movie streaming websites. This code delivers Packagist themes iOS spyware to unpatched iPhones. Furthermore, the malware steals cryptocurrency wallet seeds and sensitive device data.
Delivery
The campaign targets Vietnamese movie and comic streaming websites. Site operators unknowingly install these trojanized themes using Composer. The malicious code ships inside front-end JavaScript assets. Thirteen malicious packages operate across five vendor namespaces. Specifically, these vendors include vsmov, vsphim, haiau009, chilltvcms, and ophimcms. The threat actors fork legitimate projects and maintain the upstream author handles. As a result, the hostile republishes look completely normal.
According to the researchers, “A site operator who installs one of these themes serves malicious JavaScript to every visitor.” Mobile visitors face the most danger. The JavaScript checks the visitor device and user agent. Desktop browsers, automated bots, and direct visits pass through unharmed. Conversely, mobile visitors face a gambling redirect or the malicious Packagist themes iOS spyware chain.
Infection Chain
The attack splits mobile visitors into two distinct branches. First, the script injects a banner ad linking to a mobile gambling redirect chain. This affects both Android and iOS users. The second branch specifically targets iPhones. The loader creates a hidden element to read the exact iOS version. Subsequently, it fetches a matched WebKit exploit. The renderer stage weaponizes two public WebKit vulnerabilities. These flaws enable arbitrary read and write access inside the WebContent renderer.
Afterward, the payload pivots into the GPU process. Finally, a second stage reaches the device kernel through a specific IOKit user client. The researchers note that this kernel escape is an n-day vulnerability. Apple patched this flaw in iOS 26.1. Consequently, the chain targets iPhones that have not updated past iOS 18.6.x.
Command-and-control and data-exfiltration behaviour
Upon a successful kernel escape, the final payload harvests sensitive device information. The spyware collects keychain databases, Wi-Fi passwords, text messages, and contacts. It also grabs browser cookies, call history, location data, and photos. In August 2026, the operators updated the payload. The new version actively queries the iOS keychain for cryptocurrency wallet seeds. It specifically hunts for recovery mnemonics associated with Bitget, Phantom, Trust Wallet, and OKX.
The malware encrypts all stolen data with AES. Then, it uploads the stolen files via HTTP POST requests. The malware sends this data to a rotating pool of twenty command-and-control domains. The exploit hosts operate on FUNNULL infrastructure. The US Treasury sanctioned this provider for allegedly facilitating cryptocurrency scams. However, researchers suspect the malware operation belongs to independent tenants rather than the infrastructure provider. Commit metadata suggests a Vietnamese-operated group manages the themes.
Defense or detection guidance
Site operators must audit their installed Composer packages immediately. They should remove any themes published by the five malicious vendors. Removing these packages prevents the Packagist themes iOS spyware from reaching mobile visitors. Site administrators should also review their shipped JavaScript files for injected loaders. Developers must pin their Composer dependencies and treat front-end assets as executable code.
Furthermore, security teams should block the known exfiltration domains. iPhone users must install the latest software updates. Apple resolved the WebKit entry points in iOS 18.7.3 and iOS 26.2. Devices running these versions remain safe from the known exploit stages.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!