ophimcms is a threat-actor handle and Packagist namespace associated with a supply-chain campaign distributing trojanized Composer website themes used by Vietnamese movie and comic streaming sites. The altered themes retain expected functionality while embedding browser-side JavaScript loaders that profile visitors and selectively avoid desktop browsers, direct visitors, and automated analysis. Some mobile visitors are routed through advertising and gambling redirects, while selected iPhone users are directed to an exploit chain targeting the patched WebKit vulnerabilities CVE-2025-31277 and CVE-2025-43529 on older iOS versions. The campaign deploys spyware that collects device and account data, including Keychain contents, Wi-Fi credentials, messages, contacts, photos, browser cookies, call history, location records, and account information. Collected data is encrypted and exfiltrated to rotating command-and-control infrastructure. A later observed spyware version added searches for cryptocurrency-wallet seed phrases and mnemonic recovery material in the iPhone Keychain. Related Packagist namespaces include vsmov, vsphim, haiau009, and chilltvcms. The actor's attribution, origin, and overarching motivation have not been established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with the Composer-theme supply-chain operation that compromises streaming-site front ends, selectively exploits unpatched iPhones, exfiltrates sensitive device data, and searches keychains for cryptocurrency-wallet seed phrases and mnemonics.
Associated with the Composer-theme supply-chain operation targeting visitors of compromised streaming sites, with selective iPhone exploitation leading to spyware deployment, sensitive-data collection, and cryptocurrency wallet recovery-phrase theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.