
Malicious website themes infect unpatched iPhones with spyware when users visit a compromised site, allowing attackers to steal messages, photos, passwords, location data, and cryptocurrency wallet recovery phrases.
Socket’s Threat Research Team uncovered the packages on Packagist, where they were disguised as themes for OphimCMS and KKPhim, two Laravel-based content management systems used by Vietnamese movie and comic streaming websites.
The malicious themes were published across five Packagist vendor accounts and contain modified JavaScript that website operators unknowingly serve to their visitors.
Rather than requiring users to download an app or open a malicious attachment, the attack can begin when a vulnerable iPhone visits a site running one of the compromised themes.
Socket found that the injected code checks the visitor's device and, on targeted iPhones, launches a multi-stage exploit chain that first compromises Apple's WebKit browser engine before breaking out of the browser sandbox and gaining deeper access to the operating system.
The campaign targets iPhones from the iPhone XS through the iPhone 16 family running vulnerable iOS 18 releases, particularly iOS 18.4 through 18.6.x.

Socket
Two WebKit vulnerabilities used as entry points are already publicly known and have been added to the US Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog. Apple previously acknowledged that one of them, CVE-2025-43529, had been exploited in targeted attacks.
Socket said Apple confirmed that the kernel-level weakness used later in the chain had already been fixed before the researchers reported it.
Once the attack succeeds, the final spyware payload can collect highly sensitive information from the phone, including SMS messages, contacts, Wi-Fi passwords, photos, browser cookies, call records, location history, account information, notes, calendars, and data stored in the iOS Keychain.

Socket
The operators escalated the campaign further in August 2026, when Socket observed a newly deployed version of the spyware capable of searching the Keychain for cryptocurrency wallet secrets.
The malware specifically looks for recovery phrases and other wallet data associated with apps including Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX.
Socket linked the infrastructure serving the iOS exploit chain to FUNNULL, an infrastructure provider sanctioned by the US Treasury Department in May 2025 for facilitating cryptocurrency investment scams blamed for more than $200 million in losses.
The same malicious themes can also target mobile visitors with gambling redirects and advertising fraud, even when the iOS spyware chain does not execute.
The 13 confirmed malicious packages were published under the vsmov, vsphim, haiau009, chilltvcms, and ophimcms namespaces. Socket recommends treating other packages from those publishers as untrusted because some share the same operators and mechanisms that could be used to activate malicious JavaScript later.
For iPhone owners, the most important defense is installing Apple's latest available software updates.
Socket said the known exploit chain does not work against devices updated to iOS 26.2 or later, while users remaining on the iOS 18 branch should install at least iOS 18.7.3. Website administrators using OphimCMS or KKPhim should also remove themes distributed by the five affected Packagist vendors and review their sites for injected JavaScript.







Leave a Reply