Supply Chain Attack on art-template npm Package Delivers iOS Exploit

Supply Chain Attack on art-template npm Package Delivers iOS Exploit

First seen 22 May 2026, 11:24 UTC TechnaduGbhackersCybersecuritynewssocket.dev 88% similarity 71.0

Article Content

Browse articles
ThreatCluster

The art-template npm package, a popular JavaScript templating library, was compromised to deliver a sophisticated iOS exploit targeting Safari users. Discovered on May 20, 2026, the attack involved a watering-hole method that redirected users to a command-and-control server. The malicious payload specifically targets iOS versions 11.0 through 17.2, rejecting newer versions to avoid detection. The exploit framework is believed to be a variant of the established Coruna exploit kit, containing multiple exploit chains. This incident highlights the risks associated with supply chain vulnerabilities in widely used open-source libraries. Users of the compromised package are urged to take immediate action to mitigate potential risks. The attack has been linked to broader trends in supply chain attacks affecting software development environments.

Key Points: • The art-template npm package was backdoored to deliver a Coruna-like iOS exploit. • The attack targets Safari users on iOS versions 11.0 to 17.2, avoiding newer versions. • This incident underscores the critical risks posed by supply chain vulnerabilities.

ThreatCluster AI

Timeline

2026-05-20
Compromise of art-template detected
Socket Threat Research identified the backdoor in the art-template npm package, enabling a targeted attack on iOS Safari users.
Technadu
2026-05-22
Public disclosure of the attack
Cybersecurity news outlets reported on the backdooring of the art-template package and its implications for iOS users.
Cybersecuritynews
2026-05-22
Further analysis of the exploit framework
Reports confirmed that the exploit framework is a variant of the Coruna exploit kit, targeting specific iOS versions.
Gbhackers

Community

Browse all →