36 Malicious npm Strapi Packages Used to Deploy Redis RCE and Persistent C2 Malware
ID: 71721f73-0d63-5ac7-84c9-352f1a1c39b2
STIX ID: report--71721f73-0d63-5ac7-84c9-352f1a1c39b2
Feed Name: cybersecurityNews.com
**Supply-chain attack targeting Strapi plugins:** Thirty-six malicious npm packages posing as legitimate Strapi community plugins were published and executed via postinstall scripts to perform Redis RCE, Docker escape, credential harvesting, plaintext exfiltration of secrets (env files, private keys, Redis dumps, Docker/Kubernetes tokens), and persistent C2 access against a targeted cryptocurrency payment platform (references to “Guardarian”); researchers observed active C2 at 144.31.107.231 and payloads that probed PostgreSQL databases named guardarian, guardarian_payments, exchange, and custody. Final variants included a hidden /tmp/.node_gc.js implant with crontab persistence and a fileless node -e inline C2 agent; recommended actions include removing the malicious packages, rotating all credentials, deleting implants, auditing crontabs and processes, and revoking exposed Kubernetes service account tokens.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
