logo

Popular art-template npm Package Compromised In Watering-Hole Campaign

ID: 88228e8a-76ec-50db-944c-28cd0167f618

STIX ID: report--88228e8a-76ec-50db-944c-28cd0167f618

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Varshini

...
...

Socket’s Threat Research details a supply-chain compromise of the npm package art-template used as a watering-hole to deliver a Coruna-style Safari/WebKit exploit framework against iOS 11.0–17.2: the malicious lib/template-web.js performs sophisticated anti-bot checks, fingerprinting, WASM-based memory probing and JIT-targeted payload fetching from remote modules, beaconing victims to a C2 and selectively loading version-specific exploit payloads; compromised package versions and loader URLs are provided as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.