ended4월 4일· 1 sources
Supply Chain Assault: Malicious Strapi npm Packages Deliver Full System Compromise
npm 공급망 공격 심화: Strapi 플러그인으로 위장한 악성코드 C2 백도어 배포 중
Why it matters
This reveals a critical vulnerability in the npm supply chain where attackers can impersonate legitimate framework plugins to establish system compromise at scale. The sophisticated attack harvests infrastructure credentials (Kubernetes, Docker, Redis) and opens C2 sessions, making it especially dangerous for organizations running containerized Strapi deployments. The campaign's active nature and ecosystem-specific targeting suggest a sustained threat requiring immediate dependency audits across affected projects.
1
Sources
+0
24h
—
Growth
163d
Active
supply chainnpm malwareC2 backdoorStrapicredential theftinfrastructure attack