Affected Systems
13 malicious Composer packages on Packagist (vsmov, vsphim, haiau009, chilltvcms, ophimcms namespaces) targeting Vietnamese streaming sites using OphimCMS/KKPhim themes. iOS devices running versions 18.4 through 18.6.x (iPhone XS through iPhone 16) vulnerable to WebKit-to-kernel exploit chain. Exploits CVE-2025-31277 (patched iOS 18.6) and CVE-2025-43529 (patched iOS 18.7.3, 26.2), plus unidentified kernel escape flaw patched in iOS 26.1.
Exploitation Status
Active exploitation confirmed. Malicious packages deployed on Packagist since March 2026, with iOS exploit chain redeployed August 12, 2026. Exploits leverage known WebKit and kernel vulnerabilities similar to DarkSword exploit kit. Infrastructure hosted by Funnull, a sanctioned entity linked to cryptocurrency scams.
Business Impact
Vietnamese streaming sites unknowingly serving malicious code to all visitors. Mobile users face gambling redirects and ad-fraud. Unpatched iOS users (18.4-18.6.x) experience full device compromise: keychain extraction (including crypto wallet seeds for Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, OKX), Wi-Fi passwords, SMS, photos, contacts, browser cookies, call history, location data, and account databases exfiltrated via HTTPS to rotating C2 domains. Direct financial theft through cryptocurrency wallet seed extraction. Site operators are unwitting victims distributing malware to their user base.
Urgency
đź”´ Immediate
Recommended Actions
- Immediately audit all Composer dependencies for packages from vsmov, vsphim, haiau009, chilltvcms, and ophimcms namespaces; remove theme-dy, theme-rrdyw, theme-motchill, theme-vsmov, theme-heovl, theme-thempho, kkphim-legend, kkphim-motchill, theme-legend, and theme-pcc if installed
- Inspect all jQuery and theme scripts for injected JavaScript loading content from Funnull infrastructure or cloudfareintcdn[.]com; check Custom JS fields in OphimCMS/KKPhim configurations for malicious code
- Rotate all credentials, API keys, and secrets for affected sites and notify users of potential data breach including cryptocurrency wallet compromise
- Update all iOS devices to version 18.7.3 or later (or macOS 26.2+) to patch CVE-2025-31277, CVE-2025-43529, and kernel escape vulnerabilities
- Monitor web server logs for POST requests to /upload endpoints and connections to cloudfareintcdn[.]com or Funnull-associated domains; block identified C2 infrastructure at network perimeter
---
# Geopolitical Context
Geopolitical Context
This supply chain compromise represents a financially motivated campaign that exploits the open-source software ecosystem to target Vietnamese-language entertainment platforms and their audiences. The attack leverages sophisticated iOS exploit chains—comparable to commercial-grade tooling like DarkSword—to exfiltrate sensitive data and cryptocurrency wallet credentials. The technical sophistication, combined with infrastructure linked to Funnull (a U.S.-sanctioned entity associated with Southeast Asian cybercrime networks), suggests the operation sits at the intersection of organized cybercrime and regional illicit financial ecosystems. The targeting of Vietnamese streaming sites and the use of Vietnamese-language content platforms as distribution vectors indicates either a domestic threat actor or one with deep familiarity with Vietnam's digital entertainment landscape. This incident underscores how supply chain attacks increasingly serve as force multipliers for financially motivated actors seeking to compromise large user bases through trusted software repositories.
State Actor Alignment
The campaign appears to be the work of a Vietnamese-operated cybercriminal group rather than a state-sponsored entity, based on commit metadata and targeting patterns. However, the infrastructure dimension warrants attention: the iOS exploit chain is hosted on servers provided by Funnull, an organization sanctioned by the U.S. Treasury Department in May 2025 for enabling romance baiting scams that resulted in over $200 million in cryptocurrency losses. This connection places the operation within a broader ecosystem of Southeast Asian cybercrime infrastructure that has drawn increasing scrutiny from U.S. law enforcement and financial regulators. While there is no evidence of direct state involvement, the use of sanctioned infrastructure highlights the challenge of distinguishing between purely criminal operations and those that may enjoy tacit tolerance or protection within certain jurisdictions. The campaign's financial motivation—cryptocurrency theft and ad fraud—is consistent with organized cybercrime rather than intelligence collection objectives.
Business Impacty pro region
For Southeast Asia, this incident reflects the region's growing role as both a target and source of sophisticated cybercrime, particularly operations focused on cryptocurrency theft and online fraud. Vietnam's rapidly expanding digital economy and entertainment sector present attractive attack surfaces for actors seeking to monetize supply chain access at scale. The use of Vietnamese-language streaming platforms as distribution vectors may also indicate broader risks to regional content delivery networks and open-source software communities serving local markets. For Europe and North America, the incident serves as a reminder that supply chain threats transcend geographic boundaries: the compromised Packagist repository is globally accessible, and similar techniques could be adapted to target Western software ecosystems. The exploitation of zero-day or recently patched iOS vulnerabilities (CVE-2025-31277, CVE-2025-43529) demonstrates that financially motivated actors now deploy capabilities once associated primarily with state-sponsored groups. The Funnull infrastructure link also reinforces concerns about sanctions evasion and the resilience of cybercrime-as-a-service platforms operating across jurisdictions with limited enforcement cooperation.
Forecast
If Vietnamese authorities do not take visible enforcement action against the operators, the campaign is likely to continue with iterative payload updates and expanded targeting of regional content platforms. The actors' demonstrated ability to redeploy exploit chains (as observed in August 2026) suggests operational resilience and ongoing investment in tooling. Should Apple's iOS security updates achieve higher adoption rates in Vietnam, the threat actors may pivot to Android exploit chains or alternative data exfiltration methods that do not rely on kernel-level access. If U.S. or international pressure on Funnull-linked infrastructure intensifies, the campaign may migrate to alternative hosting providers, though this could temporarily disrupt operations. For the broader open-source ecosystem, if repository maintainers do not implement stronger vetting mechanisms for theme packages and similar high-risk categories, supply chain compromises targeting niche language communities are likely to proliferate. Organizations operating content platforms in Southeast Asia should anticipate similar attacks and prioritize dependency auditing and integrity monitoring.
