Executive Summary
The npm package art-template was used to deliver remote browser-side JavaScript after publishing control moved away from the original maintainer. Artifact analysis identifies unauthorized loaders in 4.13.3, 4.13.5, and 4.13.6; 4.13.4 does not contain the observed loader but was published by the same unauthorized account and should not be treated as a trusted recovery release SafeDep opens in a new tab Socket opens in a new tab.
The affected code is in lib/template-web.js. It executes when the browser bundle is loaded directly or included in a client-side build; the package has no malicious install hook, and the Node.js entry point does not import that browser bundle. The 2026 payload chain led to a Coruna-like iOS exploit framework with Safari/iOS gating and staged remote modules.
As of 2026-06-10, the npm registry has removed metadata and tarballs for 4.13.5 and 4.13.6, sets latest to 4.13.4, and retains 4.13.2 as the last release published by the original aui account npm registry opens in a new tab. Because 4.13.4 was published by the unauthorized v4v5qc account, defenders should pin to 4.13.2 or replace the package rather than follow latest.