Malicious Packagist Themes Target Vietnamese OphimCMS Sites with Trojanized JS
ID: b4caa144-a6f5-5087-9be0-2358304b9915
STIX ID: report--b4caa144-a6f5-5087-9be0-2358304b9915
Feed Name: securityonline.info
Socket’s Threat Research Team discovered six trojanized Packagist packages published under the ophimcms namespace that target Vietnamese OphimCMS streaming sites; the malicious themes include trojanized JavaScript (disguised as jQuery) that exfiltrates browsing history to userstat.net, injects ads, hijacks clicks, and redirects mobile users to gambling/adult sites, with ~2,750 installs and a noted second-stage payload hosted by infrastructure linked to OFAC‑sanctioned FUNNULL Technology Inc.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
