VDB

GCVE-110-OSM-2026-11910

GCVE-110-OSM-2026-11910
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 31, 2026
This package is a hostile republish of a legitimate Composer theme for OphimCMS or KKPhim, open-source PHP CMSes used to run Vietnamese-language movie and comic streaming sites. The threat actor forked the upstream project under a new vendor namespace, kept the scaffolding intact, and trojanized the shipped front-end JavaScript. Any site operator who installs it through `composer require` serves the malicious JavaScript to every visitor automatically — the victim is the site's visitor, not the developer installing the package. It is one of 13 confirmed packages across five vendor namespaces running the same campaign. The injected code runs two attack chains: a mobile ad-fraud and gambling redirect targeting iPhone, iPod, and Android user agents; and on unpatched iPhones, a WebKit-to-kernel exploit chain hosted on FUNNULL infrastructure that ends in spyware installation and crypto wallet seed theft. FUNNULL (Triad Nexus) is a Chinese-administered bulletproof hosting provider sanctioned by OFAC in May 2025 for facilitating over $200 million in cryptocurrency scams. The Packagist theme operators are assessed as a Vietnamese-operated group, attributed by UTC+07:00 commit signatures, self-declared Vietnamese identities, and their focus on Vietnamese-language piracy CMS projects. **Chain 1 — Mobile gambling/ad-fraud redirect:** `indexbottom.js` and the ADTOPLB plugin in `topinfo.js` inject a mobile banner that fires when the visitor's user agent matches iPhone, iPod, Android, or iOS. The banner links to `23[.]225[.]52[.]67:4466/vip344.html`, which meta-refreshes to `23[.]225[.]48[.]20:4466/vip/index.php`, sets a session cookie, and forwards to a randomized-subdomain `.vip` gambling landing page on port 7740. Campaign identifier: `vip344`. **Chain 2 — iOS WebKit-to-kernel exploit (FUNNULL/DarkSword):** `theme-dy` appends a loader after the shipped jQuery. The loader uses a custom base64 decoder (avoiding native `atob`) and fires on non-desktop platforms arriving with an external referrer. It pulls a second stage from `union[.]macoms[.]la/jquery.min-3.6.8.js` (the `macoms[.]la` domain family is tied to the 2024 Polyfill.io supply-chain incident). That injects `cdn[.]data-2920[.]com/app.vue.js`, which redirects to `www[.]cloudfareintcdn[.]com/in-static.js` (a Cloudflare-impersonating domain). A hidden iframe loads `start-view.html`, which reads the iOS version and delivers a version-matched WebKit exploit. The renderer stage weaponizes CVE-2025-31277 (iOS 18.4–18.5) and CVE-2025-43529 (iOS 18.6+), both patched and in CISA's KEV catalog. A GPU process pivot (IOSurface + mach messaging + forged PAC pointers) leads to a kernel escape via the AppleM2ScalerCSCDriver IOKit user client (a distinct primitive from CVE-2026-43655, confirmed fixed in iOS 26.1). The spyware payload collects keychain databases, Wi-Fi passwords, SMS database, contacts, Photos, browser cookies, call history, location, and account databases from hardcoded paths; encrypts with AES (key: `9_X1 yW,DC M= ;5`, channel: `22c75b2ee026dbbf7001cfdc2bb47855`); and exfiltrates via HTTPS POST `/upload` to a pool of 20 C2 domains that CNAME-cloak through `yunray[.]ai`. A parallel redeployment of the same chain was observed on 2026-08-12. **SHA-256 hashes (exploit stage files):** - `start-view.html`: `60b6771958cb7e553994ba6752f108575ba70e02d24affb51d8936a17eb0bf5e` - Renderer loader (`a4tt4g37f36gdd7q7kdc.js`): `d9530e8cd79ac7b3d02b04e05426653afca7075fcf7424eec4d59c6e95745933` - iOS 18.4–18.5 RCE (`a84snnb6pknt3aflt01r.js`): `92c7d246d2c163c076f783dcc19f87f5b9b9ac301b106b87a7aaea9346ce0052` - Kernel escape (`921w48jmeqvt3ygn0wwx.js`): `f2fdfddbc436acc24a654092f5205b2c5bd3208b126b2c2754ac63e7aea22298` - Spyware payload (`4ap5xpu18z70wwslqybu.js`): `9d6b58886189c0e23f706c32d3d8dda97b0b6d927ece6de07270813f070295b5` - iOS 18.6+ worker (`qljbd9a1h4a83gw8lxcj.js`): `de539a63cbe27bbd4a7db30fc796cd6dc5309c02ef5e60a3c5cf0835e5601283`

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownophimcms/theme-pccall (affected)

Browse GCVE Records

486 records in the GCVE database · Updated September 10, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›