Cybersecurity πŸ“‘ The Hacker News by The Hacker News Β· Sun, Apr 5, 2026

36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants

Cybersecurity researchers have discovered 36 malicious packages in the npm registry that are disguised as Strapi CMS plugins but come with different payloads to facilitate Redis and PostgreSQL exploitation, deploy reverse shells, harvest credentials, and drop a persistentΒ implant. "Every package contains three files (package.json, index.js, postinstall.js), has no description, repository,

πŸ’¬ 0 Crumbs ⭐ 0 saves

πŸ’¬ 0 Crumbs

Sign in and join the Nook to post a Crumb.

No Crumbs yet. Be the first!