6 Malicious Packagist Themes Ship Trojanized jQuery and FUNNULL Redirect Payloads
Blog post from Socket
Socket's Threat Research Team has discovered six malicious Composer packages within the ophimcms namespace on Packagist, which impersonate legitimate themes of the Vietnamese OphimCMS platform. These packages contain trojanized JavaScript assets that perform various malicious activities such as URL exfiltration, ad injection, and, in severe cases, redirect mobile users to gambling and adult content sites operated by FUNNULL Technology Inc., a company sanctioned by the U.S. Treasury for its involvement in cryptocurrency scams. The packages in question exploit naming conventions to deceive developers and are linked to two GitHub accounts associated with the ophimcms organization, indicating possible collaboration or a single operator using multiple identities. The infrastructure used in these attacks has ties to Chinese-origin MacCMS templates and deploys sophisticated obfuscation techniques to evade detection, posing a significant threat to users by exploiting the software supply chain. Despite the OFAC sanctions, the FUNNULL-related infrastructure remains active, highlighting the ongoing risk and the need for developers to scrutinize bundled assets within third-party themes and plugins.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.