36 malicious packages that pose as Strapi CMS plugins but have various payloads to enable Redis and PostgreSQL exploitation, deploy reverse shells, harvest passwords, and drop a permanent implant have been found by cybersecurity experts in the npm registry.
According to SafeDep, each package utilizes version 3.6.8 to appear as a mature Strapi v3 community plugin, has three files (package.json, index.js, and postinstall.js), and lacks a description, repository, or webpage.
The same naming technique is used for all identified npm packages, beginning with “strapi-plugin-” and followed by terms like “cron,” “database,” or “server” to trick unwary developers into downloading them. It’s important to remember that the official Strapi plugins are scoped at “.strapi/.”
The packages listed below were uploaded over a 13-hour period by four sock puppet accounts read more about 36 Malicious npm Packages Exploited Redis PostgreSQL to Deploy Persistent Implants.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
