Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit

Blog post from Socket

Post Details
Company
Date Published
Author
Joseph Edwards
Word Count
7,102
Company Posts That Month
27
Language
English
Hacker News Points
-
Post removed?
No
Summary

On May 20, 2026, the Socket Threat Research team discovered a sophisticated watering-hole attack targeting iOS devices through a compromised npm package called art-template, a popular JavaScript templating library. The attack involved a package supply-chain compromise, where the new maintainer of the art-template package released backdoored versions that concealed and then openly injected malicious scripts into iOS browsers. The payload, specifically targeting Safari on iOS versions 11.0 through 17.2, used various techniques to evade detection and fingerprint devices, focusing on CPU architecture and iOS version to deliver exploit kits. The package compromise mirrored characteristics of the Coruna exploit kit, attributed to Chinese threat actor UNC6691, highlighting extensive overlaps in targeting techniques and infrastructure, such as version-specific WASM memory offsets, XOR obfuscation patterns, and .xyz domain usage for command and control. The operation aimed to exploit unpatched iOS devices, avoiding newer versions like iOS 17.3+, suggesting a boundary consistent with a patched vulnerability, and featured anti-bot and anti-automation mechanisms to ensure the payload reached valid targets.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Vector Search 1 2,268 422 128 +30%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.