logo

Popular npm Package “art-template” Backdoored in Watering-Hole Attack

ID: 14454e61-e36b-5a68-a8b0-bc0619f790ae

STIX ID: report--14454e61-e36b-5a68-a8b0-bc0619f790ae

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Mayura Kathir

...
...

A malicious maintainer of the popular art-template npm package published versions that silently injected a browser loader which redirected visitors to a watering‑hole delivering a Coruna‑class Safari exploit framework targeting iPhones on iOS 11 through 17.2; the implant performs extensive fingerprinting and anti‑bot checks, beacons device info, and stages WebAssembly exploit modules. The report includes IOCs (file hashes, filenames, domains), describes exploitation behavior and scope, and urges pinning dependencies, auditing build artifacts, blocking malicious domains, and updating to iOS 17.3.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.