Executive Summary

In September 2026, cybersecurity researchers discovered 13 malicious Composer theme packages on Packagist targeting Vietnamese movie and comic streaming sites. These supply chain attacks injected JavaScript that deployed spyware on unpatched iOS devices running versions 18.4 through 18.6.x. The campaign exploited WebKit vulnerabilities CVE-2025-31277 and CVE-2025-43529 to break out of Safari's sandbox and install kernel-level malware. The sophisticated attack chain exfiltrated keychain databases, Wi-Fi passwords, SMS data, photos, and cryptocurrency wallet seeds from popular wallets including Bitget, Trust Wallet, and OKX, uploading encrypted data to command and control servers hosted on Funnull infrastructure.

This incident highlights the evolving threat landscape where supply chain attacks increasingly target mobile platforms and cryptocurrency assets. The campaign's focus on stealing wallet seeds represents a concerning escalation from traditional data theft to direct financial crime, particularly as mobile cryptocurrency adoption accelerates across Southeast Asia.

Why This Matters Now

Mobile cryptocurrency adoption is surging while iOS zero-day exploits become commoditized, creating perfect conditions for financially-motivated supply chain attacks targeting unpatched devices and digital wallets.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attack targeted iOS devices running versions 18.4 through 18.6.x, exploiting WebKit vulnerabilities that were patched in iOS 18.7.3 and macOS 26.2.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain this supply chain attack by limiting the blast radius through segmentation and controlled egress policies. The compromised streaming infrastructure would face restricted lateral movement and reduced data exfiltration pathways.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud native workload isolation could limit the scope of malicious package deployment by constraining application access to only approved repository sources and reducing attack surface exposure across streaming platform infrastructure.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust microsegmentation would likely constrain the privilege escalation scope by limiting cross-service communication pathways and reducing the attacker's ability to pivot between compromised web services and backend infrastructure components.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic enforcement could reduce the scope of data collection by limiting cross-system communication paths and constraining the malware's ability to access multiple data repositories across streaming platform backend systems.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Centralized visibility controls would likely detect and constrain command and control communications by monitoring cross-cloud traffic patterns and reducing the attacker's ability to maintain persistent communication channels with external infrastructure.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress policy enforcement would likely constrain data exfiltration by blocking unauthorized outbound HTTPS transfers and reducing the volume of sensitive data that could be transmitted to external command and control infrastructure.

Impact (Mitigations)

Despite segmentation controls, compromised user devices would still face potential cryptocurrency wallet theft, though the scope of financial impact could be reduced through limited data exfiltration pathways and constrained attack infrastructure reach.

Impact at a Glance

Affected Business Functions

  • Content Streaming Services
  • User Authentication Systems
  • Payment Processing
  • Content Management
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Comprehensive theft of iOS device data including cryptocurrency wallet seeds and mnemonics from major wallets (Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, OKX), keychain databases, Wi-Fi passwords, SMS databases, address books, photos, browser cookies, call history, location history, and account databases affecting users of Vietnamese streaming sites

Recommended Actions

  • Implement Cloud Native Security Fabric (CNSF) inline enforcement to detect and block malicious package installations and JavaScript injection attempts at the application layer
  • Deploy Egress Security & Policy Enforcement to prevent unauthorized data exfiltration to external domains, particularly blocking traffic to known malicious infrastructure like Funnull services
  • Establish Zero Trust Segmentation with least privilege policies to limit application access to sensitive device APIs and prevent privilege escalation to kernel level
  • Enable Multicloud Visibility & Control to monitor for suspicious automation patterns, repeated malformed requests, and anomalous interactions typical of supply chain attacks
  • Activate Threat Detection & Anomaly Response capabilities to baseline normal application behavior and alert on exploit kit deployment patterns and covert data collection activities

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image