Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Six Packagist Packages Linked to Trojanized jQuery Campaign

## Cybersecurity: Malicious Themes on Packagist

Cybersecurity: Malicious Themes on Packagist

Six OphimCMS themes on Packagist have been identified as distributing compromised jQuery and JavaScript, posing risks to movie-streaming sites and their users. These risks include redirects, URL exfiltration, and ad schemes linked to sanctioned infrastructure.

The malicious logic was embedded in bundled JavaScript assets, leaving the PHP code and package metadata unchanged, creating a potential supply-chain threat for Vietnamese streaming services.

The primary method involves modified jQuery files that silently redirect users, exfiltrate page URLs, inject ads, or block analysis. These activities do not compromise the server directly.

A total of 26 packages were published, with only six containing malicious payloads. The remaining themes are clean, aiding in disguising the fraudulent activity.

Socket identified six Composer packages under the ophimcms namespace that mimic legitimate OphimCMS themes: theme-dy, theme-mtyy, theme-rrdyw, theme-pcc, theme-motchill, and theme-legend.

The repositories are linked to the ophimcms GitHub organization, with README files referencing the legitimate hacoidev/ophim-core project, a tactic to suggest official endorsement.

Git history connects the activity to two GitHub accounts: binhnguyen1998822 and phantom0803. Both have write access to the ophimcms organization and have contributed to overlapping repositories, indicating either collaboration or a single operator.

These risks include redirects, URL exfiltration, and ad schemes linked to sanctioned infrastructure.
Charles Nolan · Thehackingpost

Packages linked to dev@ophim[.]cc are associated with severe redirect payloads, while those linked to opdlnf01@gmail[.]com focus on ad injection and anti-debugging logic.

This creates two monetization paths: fraudulent infrastructure and aggressive ad abuse.

The primary delivery mechanism in the affected themes is a jQuery library with obfuscated code, making detection difficult. Some packages retain original deployment artifacts like MacCMS configuration objects and tracking IDs.

The theme-dy contains a jQuery file with a URL exfiltration payload and a FUNNULL-linked stage redirecting users to unwanted sites.

The FUNNULL chain decodes a script targeting specific user scenarios to evade detection while monetizing traffic. The URL exfiltration chain poses broader risks to Vietnamese deployments.

Advertisement

Other themes embed monetization and evasion logic for various scenarios. An FBI advisory has documented linked malicious domains and restricts U.S. transactions with the network.

Theme-rrdyw injects ads and tracking without consent. Theme-pcc hijacks clicks, redirecting users to ads. Theme-motchill forces ad viewing. Theme-legend focuses on anti-debugging.

The operation is linked to FUNNULL Technology Inc., sanctioned for supporting cryptocurrency fraud. Despite sanctions, the FUNNULL-controlled payload remains active.

An estimated 2,750 installations of these themes may have exposed sites to URL leaks, unwanted redirects, or ad monetization.

Socket advises removing the malicious themes, auditing traffic for specific domains, and inspecting JavaScript for obfuscated code, particularly where integrity checks are absent.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories