Six Packagist Packages Linked to Trojanized jQuery Campaign
## Cybersecurity: Malicious Themes on Packagist
Cybersecurity: Malicious Themes on Packagist
Six OphimCMS themes on Packagist have been identified as distributing compromised jQuery and JavaScript, posing risks to movie-streaming sites and their users. These risks include redirects, URL exfiltration, and ad schemes linked to sanctioned infrastructure.
The malicious logic was embedded in bundled JavaScript assets, leaving the PHP code and package metadata unchanged, creating a potential supply-chain threat for Vietnamese streaming services.
The primary method involves modified jQuery files that silently redirect users, exfiltrate page URLs, inject ads, or block analysis. These activities do not compromise the server directly.
A total of 26 packages were published, with only six containing malicious payloads. The remaining themes are clean, aiding in disguising the fraudulent activity.
Socket identified six Composer packages under the ophimcms namespace that mimic legitimate OphimCMS themes: theme-dy, theme-mtyy, theme-rrdyw, theme-pcc, theme-motchill, and theme-legend.
The repositories are linked to the ophimcms GitHub organization, with README files referencing the legitimate hacoidev/ophim-core project, a tactic to suggest official endorsement.
Git history connects the activity to two GitHub accounts: binhnguyen1998822 and phantom0803. Both have write access to the ophimcms organization and have contributed to overlapping repositories, indicating either collaboration or a single operator.
These risks include redirects, URL exfiltration, and ad schemes linked to sanctioned infrastructure.
Packages linked to dev@ophim[.]cc are associated with severe redirect payloads, while those linked to opdlnf01@gmail[.]com focus on ad injection and anti-debugging logic.
This creates two monetization paths: fraudulent infrastructure and aggressive ad abuse.
The primary delivery mechanism in the affected themes is a jQuery library with obfuscated code, making detection difficult. Some packages retain original deployment artifacts like MacCMS configuration objects and tracking IDs.
The theme-dy contains a jQuery file with a URL exfiltration payload and a FUNNULL-linked stage redirecting users to unwanted sites.
The FUNNULL chain decodes a script targeting specific user scenarios to evade detection while monetizing traffic. The URL exfiltration chain poses broader risks to Vietnamese deployments.
Other themes embed monetization and evasion logic for various scenarios. An FBI advisory has documented linked malicious domains and restricts U.S. transactions with the network.
Theme-rrdyw injects ads and tracking without consent. Theme-pcc hijacks clicks, redirecting users to ads. Theme-motchill forces ad viewing. Theme-legend focuses on anti-debugging.
The operation is linked to FUNNULL Technology Inc., sanctioned for supporting cryptocurrency fraud. Despite sanctions, the FUNNULL-controlled payload remains active.
An estimated 2,750 installations of these themes may have exposed sites to URL leaks, unwanted redirects, or ad monetization.
Socket advises removing the malicious themes, auditing traffic for specific domains, and inspecting JavaScript for obfuscated code, particularly where integrity checks are absent.
Based on reporting by GBHackers.
