Thirteen trojanized Composer theme packages for the OphimCMS and KKPhim streaming-site ecosystems injected malicious JavaScript into every visitor page, sending users to gambling and ad-fraud content and selectively attacking externally referred, non-desktop visitors. On vulnerable iPhones, the packages delivered a FUNNULL-hosted WebKit-to-kernel exploit chain targeting CVE-2025-31277, CVE-2025-43529, and an AppleM2ScalerCSCDriver kernel primitive; the campaign targeted iOS 18.4 through 18.6.x rather than updated versions.
The spyware harvested keychain data, messages, photos, browser cookies, location history, and cryptocurrency wallet seed phrases, then exfiltrated them to rotating command-and-control infrastructure. Operators redeployed the exploit chain and added wallet theft capabilities, while FUNNULL-linked infrastructure has continued operating after sanctions, with activity reportedly being separated from the FUNNULL CDN brand.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
The operators rotated the second-stage loader for the iOS exploitation chain again.
Operators redeployed the complete FUNNULL-hosted iOS exploit chain under new filenames. The redeployed spyware added keychain queries targeting wallet data associated with Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX.
OFAC sanctioned Liu Lizhi for facilitating more than $200 million in cryptocurrency scams. The report links FUNNULL infrastructure to systems administered by Liu Lizhi.
Attackers distributed 13 trojanized Composer/Packagist website-theme packages across five namespaces, causing Vietnamese movie and comic streaming sites to serve malicious JavaScript to visitors. The loaders selectively targeted qualifying iPhone users for the FUNNULL-hosted iOS exploit chain while redirecting other mobile traffic to gambling content.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 57 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcecyberaccord.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcecyberveille.ch
Open sourcesocket.dev
Open sourcesilentpush.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.