<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[(safedep.io) Compromised art-template npm Package Delivers Coruna iOS Exploit Kit via Supply Chain Attack]]></title><description><![CDATA[<p>(safedep.io) Compromised art-template npm Package Delivers Coruna iOS Exploit Kit via Supply Chain Attack</p><p>Critical supply-chain compromise detected in the npm package art-template (4.13.3–4.13.6), delivering the Coruna iOS exploit kit via account takeover. The attack targets iPhone users with a multi-stage payload exploiting CVE-2024-23222 (CVSS 8.8) and 22 other vulnerabilities, leading to native code execution and cryptocurrency wallet theft via PLASMAGRID.</p><p>In brief - A maintainer account takeover enabled malicious versions of the widely used art-template npm package to inject browser-based payloads. The attack chain delivers the Coruna exploit kit, exploiting iOS vulnerabilities (including CVE-2024-23222) to deploy PLASMAGRID, a cryptocurrency wallet stealer. Active C2 infrastructure and throwaway npm accounts highlight persistent supply chain risks.</p><p>Technically - Unauthorized modifications to template-web.js in art-template versions 4.13.3–4.13.6 appended code loading external scripts from v3.jiathis[.]com. The attack stages include Baidu Analytics tracking, iPhone-specific iframes, device fingerprinting, and delivery of the Coruna exploit kit (606KB, 14 modules). CVE-2024-23222 (JavaScriptCore type confusion) is exploited via WebAssembly type confusion and JIT heap spraying, bypassing ASLR through dyld shared cache parsing. ARM64 shellcode executes syscalls (ptrace, csops) for native code execution. PLASMAGRID targets wallets like MetaMask, with C2 (l1ewsu3yjkqeroy[.]xyz) fronted by Cloudflare. Throwaway npm accounts (v4v5qc, npmpacketmaintainmember7) and GitHub renames (aui → goofychris) maintained persistence.</p><p>Source: <a href="https://safedep.io/art-template-npm-supply-chain-compromise" rel="nofollow noopener"><span>https://</span><span>safedep.io/art-template-npm-su</span><span>pply-chain-compromise</span></a></p><p><a href="https://swecyb.com/tags/Cybersecurity" rel="tag">#<span>Cybersecurity</span></a> <a href="https://swecyb.com/tags/ThreatIntel" rel="tag">#<span>ThreatIntel</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/d034517b-019a-4865-bef5-952f96688b85/safedep.io-compromised-art-template-npm-package-delivers-coruna-ios-exploit-kit-via-supply-chain-attack</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 10:39:22 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/d034517b-019a-4865-bef5-952f96688b85.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 20 May 2026 16:15:44 GMT</pubDate><ttl>60</ttl></channel></rss>