36 Malicious npm Strapi Packages Used to Deploy Redis RCE and Persistent C2 Malware

A coordinated supply chain attack has been uncovered targeting developers who build applications on Strapi, a widely used open-source content management system. Thirty-six malicious npm packages disguised as legitimate Strapi plugins were published to the npm registry, carrying payloads designed to exploit Redis for remote code execution, steal credentials, and establish persistent command-and-control access on […]

The post 36 Malicious npm Strapi Packages Used to Deploy Redis RCE and Persistent C2 Malware appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: