In short: On September 2, 2026, Socket Security researchers exposed a watering-hole campaign: 13 malicious Packagist themes for OphimCMS and KKPhim video CMSs had been silently attacking visitors to Vietnamese film and comic sites since mid-August 2026. A hidden JavaScript deployed a two-stage WebKit exploit chain (CVE-2025-31277 and CVE-2025-43529) that escaped the browser sandbox, reached the iOS kernel, and exfiltrated keychain data, passwords, messages, photos, and crypto wallet seeds from iPhone XS through iPhone 16 running iOS 18.4–18.6.x. Apple patched both CVEs in iOS 18.7.3 and iOS 26.2.
How attackers reached iPhones through a regular webpage
The campaign used a classic watering-hole technique: instead of targeting iPhones directly, attackers poisoned popular Vietnamese streaming and comic websites. A user opened a familiar page in Safari and, without any further interaction, the exploit chain fired silently in the background. Read more about how browser-based attacks work and how to harden your devices on our cybersecurity blog.
The entry point was Packagist — the official Composer package registry used by millions of PHP-powered websites. Attackers published 13 counterfeit theme packages mimicking legitimate templates for OphimCMS and KKPhim. Webmasters installed the themes through their normal update workflow, unaware each package included malicious JavaScript.
Each theme injected a hidden iframe that:
- Fingerprinted the visitor's iOS version.
- Fetched the appropriate exploit: CVE-2025-31277 bypassed WebKit validation; CVE-2025-43529 escaped the browser sandbox.
- Chained both stages to achieve kernel-level access to the device.
- Silently encrypted the collected data with AES and uploaded it via HTTPS POST to a rotating pool of command-and-control servers.
The server infrastructure was provided by FUNNULL, the same entity sanctioned by the US Treasury for supporting cryptocurrency fraud platforms. According to SecurityLab, the campaign ran from around August 12 until researchers published their findings on September 2, 2026.
What data was stolen
A successful infection gave attackers full access to the victim's personal data. The spyware automatically exfiltrated:
- Keychain database — all saved passwords for websites, banking apps, and Wi-Fi networks.
- Wi-Fi passwords — enabling access to the victim's home network.
- SMS and iMessage history — including two-factor authentication codes.
- Photo library — the complete camera roll.
- Address book — for follow-on phishing against the victim's contacts.
- Browser cookies and history — to hijack active sessions and bypass 2FA without a password.
- Call history and location data.
- Crypto wallet seed phrases — mnemonic recovery phrases for Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX.
The crypto seed theft is particularly severe: unlike a password, a mnemonic phrase cannot be changed — exposure means irreversible loss of all wallet assets. Stolen session cookies allowed account access while bypassing two-factor authentication entirely. Learn how to build layered protection in the LiMP VPN features section.
Which devices are affected and what Apple did
The exploit chain targeted iOS 18 and affected iPhone XS, XS Max, XR, 11, 12, 13, 14, 15, and 16 running iOS 18.4, 18.5, 18.6, or 18.6.x. Devices on iOS 26.x were not in scope for this campaign.
Apple resolved both vulnerabilities in two separate updates released shortly after Socket Security's disclosure:
- iOS 18.7.3 — for devices not compatible with iOS 26;
- iOS 26.2 — for iPhone 16 and later models.
The malicious packages — vsmov, vsphim, haiau009, chilltvcms, and ophimcms — were removed from the Packagist registry after the security team was notified.
What to do right now
If you own an iPhone, take these steps immediately:
- Update iOS now. Open Settings → General → Software Update and install iOS 18.7.3 (or iOS 26.2 for iPhone 16+). This is the single most important action.
- Change passwords for critical accounts: email, banking apps, and messaging services. Use a unique password for every service.
- If you hold crypto — move your assets to a new wallet created on a clean device. A compromised seed phrase cannot be reset.
- Review active sessions on Google, Apple ID, and social networks — sign out any unfamiliar devices.
- Enable Lockdown Mode if you handle particularly sensitive data. It restricts the browser features this attack exploited.
For network-level protection, LiMP VPN encrypts your traffic when connecting over public Wi-Fi or untrusted networks, preventing interception in transit. Our zero-logs policy means your connection history is never stored or shared.
