Executive Summary
In September 2026, cybersecurity researchers discovered 13 malicious Composer theme packages on Packagist targeting Vietnamese movie and comic streaming sites. These supply chain attacks injected JavaScript that deployed spyware on unpatched iOS devices running versions 18.4 through 18.6.x. The campaign exploited WebKit vulnerabilities CVE-2025-31277 and CVE-2025-43529 to break out of Safari's sandbox and install kernel-level malware. The sophisticated attack chain exfiltrated keychain databases, Wi-Fi passwords, SMS data, photos, and cryptocurrency wallet seeds from popular wallets including Bitget, Trust Wallet, and OKX, uploading encrypted data to command and control servers hosted on Funnull infrastructure.
This incident highlights the evolving threat landscape where supply chain attacks increasingly target mobile platforms and cryptocurrency assets. The campaign's focus on stealing wallet seeds represents a concerning escalation from traditional data theft to direct financial crime, particularly as mobile cryptocurrency adoption accelerates across Southeast Asia.
Why This Matters Now
Mobile cryptocurrency adoption is surging while iOS zero-day exploits become commoditized, creating perfect conditions for financially-motivated supply chain attacks targeting unpatched devices and digital wallets.
Attack Path Analysis
Attackers compromised 13 malicious Composer packages on Packagist targeting Vietnamese streaming sites, injecting JavaScript to exploit unpatched iOS devices. The malware exploited WebKit vulnerabilities CVE-2025-31277 and CVE-2025-43529 to escape sandbox, escalate to kernel privileges, and exfiltrate keychain data, cryptocurrency wallet seeds, and sensitive device information to command and control infrastructure hosted on sanctioned Funnull services.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actors published 13 malicious Composer theme packages on Packagist repository, targeting Vietnamese movie and comic streaming sites that unknowingly installed trojanized OphimCMS and KKPhim themes
Related CVEs
CVE-2025-31277
CVSS 8.8A WebKit vulnerability that allows remote attackers to execute arbitrary code through crafted web content, leading to potential sandbox escape.
Affected Products:
Apple iOS – < 18.6
Apple Safari – < 18.6
Exploit Status:
exploited in the wildCVE-2025-43529
CVSS 8.8A WebKit vulnerability allowing arbitrary code execution that can be chained with other exploits for privilege escalation on iOS devices.
Affected Products:
Apple iOS – < 18.7.3, < 26.2
Apple Safari – < 18.7.3
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Supply Chain Compromise: Compromise Software Dependencies and Development Tools
Drive-by Compromise
Process Injection
Exploitation for Privilege Escalation
Credentials from Password Stores: Keychain
Exfiltration Over C2 Channel
Data from Local System
Encrypted Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Integrity and Anti-Tampering
Control ID: 11.6.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – Third-party Risk Management
Control ID: Article 28
CISA ZTMM 2.0 – Application Security
Control ID: Function 4
NIS2 Directive – Supply Chain Security
Control ID: Article 21.2(e)
GDPR – Security of Processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Entertainment/Movie Production
Vietnamese movie streaming sites targeted by malicious Composer packages deploying iOS spyware, cryptocurrency theft malware affecting content platforms and user data security.
Computer Software/Engineering
Supply chain attacks through Packagist theme packages exploiting WebKit vulnerabilities CVE-2025-31277 and CVE-2025-43529, compromising software development repositories and deployment pipelines.
Financial Services
iOS keychain cryptocurrency wallet seed theft targeting Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX through mobile Safari exploitation chains.
Consumer Electronics
Unpatched iPhone devices running iOS 18.4-18.6.x vulnerable to WebKit-to-kernel exploits enabling comprehensive data exfiltration including Photos, SMS, location history, and credentials.
Sources
- 13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seedshttps://thehackernews.com/2026/09/13-malicious-packagist-packages-target.htmlVerified
- Packagist Themes Used to Deploy iOS Spywarehttps://socket.dev/blog/packagist-themes-ios-spywareVerified
- Apple Security Updateshttps://support.apple.com/en-us/125884Verified
- US Sanctions Funnull for $200M Romance Scam Infrastructurehttps://thehackernews.com/2025/05/us-sanctions-funnull-for-200m-romance.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain this supply chain attack by limiting the blast radius through segmentation and controlled egress policies. The compromised streaming infrastructure would face restricted lateral movement and reduced data exfiltration pathways.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud native workload isolation could limit the scope of malicious package deployment by constraining application access to only approved repository sources and reducing attack surface exposure across streaming platform infrastructure.
Control: Zero Trust Segmentation
Mitigation: Zero trust microsegmentation would likely constrain the privilege escalation scope by limiting cross-service communication pathways and reducing the attacker's ability to pivot between compromised web services and backend infrastructure components.
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement could reduce the scope of data collection by limiting cross-system communication paths and constraining the malware's ability to access multiple data repositories across streaming platform backend systems.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility controls would likely detect and constrain command and control communications by monitoring cross-cloud traffic patterns and reducing the attacker's ability to maintain persistent communication channels with external infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Egress policy enforcement would likely constrain data exfiltration by blocking unauthorized outbound HTTPS transfers and reducing the volume of sensitive data that could be transmitted to external command and control infrastructure.
Despite segmentation controls, compromised user devices would still face potential cryptocurrency wallet theft, though the scope of financial impact could be reduced through limited data exfiltration pathways and constrained attack infrastructure reach.
Impact at a Glance
Affected Business Functions
- Content Streaming Services
- User Authentication Systems
- Payment Processing
- Content Management
Estimated downtime: 7 days
Estimated loss: $500,000
Comprehensive theft of iOS device data including cryptocurrency wallet seeds and mnemonics from major wallets (Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, OKX), keychain databases, Wi-Fi passwords, SMS databases, address books, photos, browser cookies, call history, location history, and account databases affecting users of Vietnamese streaming sites
Recommended Actions
Key Takeaways & Next Steps
- • Implement Cloud Native Security Fabric (CNSF) inline enforcement to detect and block malicious package installations and JavaScript injection attempts at the application layer
- • Deploy Egress Security & Policy Enforcement to prevent unauthorized data exfiltration to external domains, particularly blocking traffic to known malicious infrastructure like Funnull services
- • Establish Zero Trust Segmentation with least privilege policies to limit application access to sensitive device APIs and prevent privilege escalation to kernel level
- • Enable Multicloud Visibility & Control to monitor for suspicious automation patterns, repeated malformed requests, and anomalous interactions typical of supply chain attacks
- • Activate Threat Detection & Anomaly Response capabilities to baseline normal application behavior and alert on exploit kit deployment patterns and covert data collection activities



