Technadu
Supply Chain Attack on art-template npm Package Delivers iOS Exploit
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The art-template npm package, a popular JavaScript templating library, was compromised to deliver a sophisticated iOS exploit targeting Safari users. Discovered on May 20, 2026, the attack involved a watering-hole method that redirected users to a command-and-control server. The malicious payload specifically targets iOS versions 11.0 through 17.2, rejecting newer versions to avoid detection. The exploit framework is believed to be a variant of the established Coruna exploit kit, containing multiple exploit chains. This incident highlights the risks associated with supply chain vulnerabilities in widely used open-source libraries. Users of the compromised package are urged to take immediate action to mitigate potential risks. The attack has been linked to broader trends in supply chain attacks affecting software development environments.
Key Points: • The art-template npm package was backdoored to deliver a Coruna-like iOS exploit. • The attack targets Safari users on iOS versions 11.0 to 17.2, avoiding newer versions. • This incident underscores the critical risks posed by supply chain vulnerabilities.