logo

Packagist Themes Deliver Trojanized jQuery in OphimCMS Supply Chain Attack

ID: d7bb5d5f-ed11-547d-9076-5706e645f34b

STIX ID: report--d7bb5d5f-ed11-547d-9076-5706e645f34b

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-17

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A supply-chain campaign was found on Packagist where six OphimCMS themes (ophimcms/theme-dy, theme-mtyy, theme-rrdyw, theme-pcc, theme-motchill, and theme-legend) include trojanized JavaScript (obfuscated jQuery and Sizzle modifications) that exfiltrates page URLs to userstat.net, injects ads and analytics, hijacks clicks, disables debugging, and, under conditions, redirects mobile users to FUNNULL-linked gambling/ad sites (union.macoms.la). The packages remain live at reporting time, are tied via Git history to the ophimcms GitHub organization and two operator identities, and are estimated to have roughly 2,750 installations; recommended actions include removing the malicious packages, auditing theme JS for unexpected network calls, enforcing dependency allowlists, and scanning front-end assets for obfuscated behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.