Back to IntelRead Original Source
Intel Node
36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants
lowadvisory2026-04-05T05:07:00+00:00source excerpt
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
Cybersecurity researchers have discovered 36 malicious packages in the npm registry that are disguised as Strapi CMS plugins but come with different payloads to facilitate Redis and PostgreSQL exploitation, deploy reverse shells, harvest credentials, and drop a persistent implant.