logo

Hackers Backdoor Popular art-template npm Package to Launch Watering-Hole Attacks

ID: 9964cd02-c0ba-5fa6-ac13-603814aa5265

STIX ID: report--9964cd02-c0ba-5fa6-ac13-603814aa5265

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-05-22

Date Updated: 2026-05-23

Author: Tushar Subhra Dutta

...
...

A maintained art-template npm package was taken over by an unknown actor who modified versions 4.13.3, 4.13.5, and 4.13.6 to inject a JavaScript implant that loads a Coruna-like exploit framework. The implant fingerprints visitors, performs multi-layer anti-bot checks, targets Safari on iOS 11.0–17.2 (with a cutoff aligned to a WebKit patch for CVE-2024-23222), and fetches version-specific remote exploit modules; the report includes domains, URLs, file hashes, package versions, a session key and campaign code, plus mitigation guidance to audit and lock dependencies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.