chilltvcms is a threat-actor handle and Packagist vendor namespace associated with a supply-chain campaign involving trojanized Composer website themes. The malicious themes were used by Vietnamese movie and comic streaming websites and retained expected theme functionality while embedding browser-side JavaScript loaders. Sites that installed the packages served the loaders to visitors. The loaders fingerprint devices and referral sources, avoiding desktop browsers, automated scanners, and direct visitors to reduce exposure. Some mobile visitors were routed through advertising and gambling redirect chains. Selected iPhone visitors were directed to a multistage exploit chain that identified iOS versions and targeted patched WebKit vulnerabilities CVE-2025-31277 and CVE-2025-43529, followed by a kernel-escape stage on susceptible older iOS versions. The resulting iOS spyware collected Keychain data, Wi-Fi credentials, messages, contacts, photographs, browser cookies, call history, location information, and account data. It encrypted and exfiltrated collected data to rotating command-and-control infrastructure. A later observed variant also searched Keychain data for cryptocurrency-wallet seed phrases and mnemonic recovery material. The campaign is also associated with the Packagist namespaces vsmov, vsphim, haiau009, and ophimcms.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with a malicious Composer-theme campaign that injects browser-side loaders into streaming websites and selectively deploys iPhone exploitation and spyware, while redirecting other mobile traffic to gambling and advertising infrastructure.
Associated with the malicious Composer-theme campaign that compromises streaming-site front ends to deliver device-selective redirects, iPhone exploitation, spyware, and wallet-recovery-data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.