Visiting a Vietnamese streaming site — without clicking a link or downloading a file — can silently drain a crypto wallet. Socket’s Threat Research Team identified 13 malicious Composer/Packagist theme packages, spread across five vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms), injecting JavaScript into streaming sites built on OphimCMS and KKPhim. The payload runs two attacks simultaneously: gambling redirects and ad injection for every mobile visitor, and a full WebKit-to-kernel exploit chain targeting iPhones on iOS 18.4 through 18.6.x.
13 Malicious Packages Turn iPhones Into Crypto Theft Targets
Visiting a Vietnamese streaming site — without clicking a link or downloading a file — can silently drain a crypto wallet. Socket’s Threat Research Team identified 13 malicious Composer/Packagist theme packages, spread across five…
Gadget Review
Publisher
Sep 2, 2026 at 3:20 PM UTC · 3 分で読める

How a Movie Site Empties Your Wallet
The attack requires nothing from you — just a page load on an unpatched iPhone.
Buried in legitimate-looking theme code, the injected script drops a hidden iframe, detects the visitor’s iOS version, and loads a version-specific exploit payload. Think of it like a burglar who checks the lock model before choosing the right pick. The chain weaponizes two public WebKit vulnerabilities — CVE-2025-31277 (patched in iOS 18.6) and CVE-2025-43529 (patched in iOS 18.7.3 and 26.2) — to escape Safari’s sandbox, pivot through the GPU process, and reach the kernel via the AppleM2ScalerCSCDriver IOKit user client. The result is full kernel read/write access. Socket’s researcher Kush Pandya compares the structure to the DarkSword exploit kit.
Article Intelligence
Topics
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
