{
  "title": "art-template npm Coruna Browser Exploit Compromise",
  "summary": "Unauthorized art-template releases 4.13.3, 4.13.5, and 4.13.6 modified the browser bundle to load remote JavaScript. The later chain delivered a Coruna iOS exploit framework; npm has removed 4.13.5 and 4.13.6, while 4.13.2 remains the last verified clean release.",
  "date": "2026-05-24",
  "severity": "high",
  "tags": [
    "supply-chain",
    "npm",
    "browser",
    "javascript",
    "exploit-delivery"
  ],
  "sources_count": 5,
  "indicators": {
    "slug": "art-template-coruna-npm-compromise",
    "since": "2026-05-24T00:00:00Z",
    "until": "unknown",
    "ecosystem": "",
    "cves": [],
    "cwes": [],
    "advisoryIds": [],
    "products": [],
    "packages": [],
    "versions": [],
    "affectedVersions": [],
    "fixedVersions": [],
    "files": [],
    "paths": [],
    "services": [],
    "domains": [
      "git.youzzjizz.com",
      "v3.jiathis.com",
      "utaq.cfww.shop",
      "cfww.shop",
      "l1ewsu3yjkqeroy.xyz",
      "hm.baidu.com"
    ],
    "urls": [
      "https://git.youzzjizz.com/git.js",
      "https://v3.jiathis.com/code/jia.js?uid=artemplate",
      "https://v3.jiathis.com/code/art.js",
      "https://utaq.cfww.shop/gooll/49554fde7424c31c.js",
      "https://l1ewsu3yjkqeroy.xyz/api/ip-sync/sync"
    ],
    "ips": [],
    "hashes": [
      "f31bdd069fe7966ae11be1f78ee5dd44445938856dd1df12379e0e84a6851f5c",
      "8064d4e0322f069b3dba13e7957ff0ca7dab7984",
      "6e79ae622b7ef30f31fdbcc2dc65339e"
    ],
    "processPatterns": [],
    "networkPatterns": [],
    "telemetrySelectors": []
  }
}