ended4월 4일· 1 sources

Supply Chain Assault: Malicious Strapi npm Packages Deliver Full System Compromise

npm 공급망 공격 심화: Strapi 플러그인으로 위장한 악성코드 C2 백도어 배포 중

Why it matters

This reveals a critical vulnerability in the npm supply chain where attackers can impersonate legitimate framework plugins to establish system compromise at scale. The sophisticated attack harvests infrastructure credentials (Kubernetes, Docker, Redis) and opens C2 sessions, making it especially dangerous for organizations running containerized Strapi deployments. The campaign's active nature and ecosystem-specific targeting suggest a sustained threat requiring immediate dependency audits across affected projects.

1
Sources
+0
24h
Growth
163d
Active
supply chainnpm malwareC2 backdoorStrapicredential theftinfrastructure attack

Sources

Related Issues