logo

36 Malicious Strapi npm Packages Deliver Redis RCE, Persistent C2 Malware

ID: ae353e3d-25ec-5897-adc2-e51229d240ba

STIX ID: report--ae353e3d-25ec-5897-adc2-e51229d240ba

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-04-06

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A coordinated supply-chain campaign involving 36 malicious npm packages posing as Strapi plugins delivered multiple malware variants (RCE via Redis CONFIG, Docker escape attempts, bash/Python reverse shells, credential and secrets exfiltration, PostgreSQL dumps, and persistent Node.js implants) with evidence of targeting a cryptocurrency payment platform and active C2 infrastructure; package names, versions, and author accounts are enumerated as IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.