Popular npm Package “art-template” Backdoored in Watering-Hole Attack
ID: 14454e61-e36b-5a68-a8b0-bc0619f790ae
STIX ID: report--14454e61-e36b-5a68-a8b0-bc0619f790ae
Feed Name: GBHackers
A malicious maintainer of the popular art-template npm package published versions that silently injected a browser loader which redirected visitors to a watering‑hole delivering a Coruna‑class Safari exploit framework targeting iPhones on iOS 11 through 17.2; the implant performs extensive fingerprinting and anti‑bot checks, beacons device info, and stages WebAssembly exploit modules. The report includes IOCs (file hashes, filenames, domains), describes exploitation behavior and scope, and urges pinning dependencies, auditing build artifacts, blocking malicious domains, and updating to iOS 17.3.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
