logo

36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants

ID: df49c685-3fb7-5882-92d4-789b5b9ec7d5

STIX ID: report--df49c685-3fb7-5882-92d4-789b5b9ec7d5

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-04-05

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers discovered 36 malicious npm packages masquerading as Strapi v3 plugins that execute postinstall scripts to perform Redis and PostgreSQL exploitation, deploy reverse shells, harvest credentials, exfiltrate secrets, and install persistent implants; the campaign (uploaded by multiple sock‑puppet accounts) likely targets cryptocurrency platforms and is part of a wider wave of open‑source supply chain attacks, so users who installed these packages should assume compromise and rotate credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.