Packagist Themes Deliver Trojanized jQuery in OphimCMS Supply Chain Attack
ID: d7bb5d5f-ed11-547d-9076-5706e645f34b
STIX ID: report--d7bb5d5f-ed11-547d-9076-5706e645f34b
Feed Name: GBHackers
A supply-chain campaign was found on Packagist where six OphimCMS themes (ophimcms/theme-dy, theme-mtyy, theme-rrdyw, theme-pcc, theme-motchill, and theme-legend) include trojanized JavaScript (obfuscated jQuery and Sizzle modifications) that exfiltrates page URLs to userstat.net, injects ads and analytics, hijacks clicks, disables debugging, and, under conditions, redirects mobile users to FUNNULL-linked gambling/ad sites (union.macoms.la). The packages remain live at reporting time, are tied via Git history to the ophimcms GitHub organization and two operator identities, and are estimated to have roughly 2,750 installations; recommended actions include removing the malicious packages, auditing theme JS for unexpected network calls, enforcing dependency allowlists, and scanning front-end assets for obfuscated behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
