Home / Companies / Socket / Blog / Post Details
Content Deep Dive

6 Malicious Packagist Themes Ship Trojanized jQuery and FUNNULL Redirect Payloads

Blog post from Socket

Post Details
Company
Date Published
Author
Kush Pandya
Word Count
2,517
Company Posts That Month
42
Language
English
Hacker News Points
-
Post removed?
No
Summary

Socket's Threat Research Team has discovered six malicious Composer packages within the ophimcms namespace on Packagist, which impersonate legitimate themes of the Vietnamese OphimCMS platform. These packages contain trojanized JavaScript assets that perform various malicious activities such as URL exfiltration, ad injection, and, in severe cases, redirect mobile users to gambling and adult content sites operated by FUNNULL Technology Inc., a company sanctioned by the U.S. Treasury for its involvement in cryptocurrency scams. The packages in question exploit naming conventions to deceive developers and are linked to two GitHub accounts associated with the ophimcms organization, indicating possible collaboration or a single operator using multiple identities. The infrastructure used in these attacks has ties to Chinese-origin MacCMS templates and deploys sophisticated obfuscation techniques to evade detection, posing a significant threat to users by exploiting the software supply chain. Despite the OFAC sanctions, the FUNNULL-related infrastructure remains active, highlighting the ongoing risk and the need for developers to scrutinize bundled assets within third-party themes and plugins.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Real-time 3 6,457 1,307 242 +28%
MCP 1 4,488 443 150 +34%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.