
13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds
Thirteen malicious Packagist themes expose visitors on unpatched iPhones to a WebKit-to-kernel exploit chain that steals device data and wallet seeds.
Supply Chain Attack Campaign
FUNNULL is a malicious Composer theme cluster on Packagist that operates as a watering-hole malware delivery framework. The trojanized themes inject JavaScript into every page of the Vietnamese movie and comic streaming sites that install them, and the injected payloads are extensible and swapped as the campaign evolves, but the main targets are iPhone users, their on-device data, and their cryptocurrency wallets and seed phrases. The campaign has been active since at least December 2025. The injected loaders gate on platform and referrer so that mobile visitors are served the payload while desktop browsers, bots, and direct visits are passed over, then pull a second stage from FUNNULL (Triad Nexus) infrastructure through a chain of CNAME-cloaked front domains that rotate as they are burned and can be repointed to a new C2 endpoint at any time. On iPhones the second stage loads a WebKit-to-kernel exploit chain that installs spyware and exfiltrates keychain data, messages, contacts, photos, location, and wallet seed phrases; on other mobile devices it runs a gambling and ad-fraud redirect. Execution is achieved by shipping the malicious code inside the theme's front-end assets and by rendering the theme's admin "Custom JS" fields into every page unescaped, which lets an operator arm or update the payload without publishing a new package.
Ecosystems: composer

Thirteen malicious Packagist themes expose visitors on unpatched iPhones to a WebKit-to-kernel exploit chain that steals device data and wallet seeds.

Six malicious Packagist packages posing as OphimCMS themes contain trojanized jQuery that exfiltrates URLs, injects ads, and loads FUNNULL-linked redirects.