Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit
Blog post from Socket
On May 20, 2026, the Socket Threat Research team discovered a sophisticated watering-hole attack targeting iOS devices through a compromised npm package called art-template, a popular JavaScript templating library. The attack involved a package supply-chain compromise, where the new maintainer of the art-template package released backdoored versions that concealed and then openly injected malicious scripts into iOS browsers. The payload, specifically targeting Safari on iOS versions 11.0 through 17.2, used various techniques to evade detection and fingerprint devices, focusing on CPU architecture and iOS version to deliver exploit kits. The package compromise mirrored characteristics of the Coruna exploit kit, attributed to Chinese threat actor UNC6691, highlighting extensive overlaps in targeting techniques and infrastructure, such as version-specific WASM memory offsets, XOR obfuscation patterns, and .xyz domain usage for command and control. The operation aimed to exploit unpatched iOS devices, avoiding newer versions like iOS 17.3+, suggesting a boundary consistent with a patched vulnerability, and featured anti-bot and anti-automation mechanisms to ensure the payload reached valid targets.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Vector Search | 1 | 2,268 | 422 | 128 | +30% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.