36 Malicious Strapi npm Packages Deliver Redis RCE and C2 Malware

36 Malicious Strapi npm Packages Deliver Redis RCE and C2 Malware

First seen 6 Apr 2026, 05:56 UTC GbhackersCybersecuritynews 94% similarity 69.0

Article Content

Browse articles
ThreatCluster

A coordinated supply chain attack has been discovered involving 36 malicious npm packages that impersonate Strapi CMS plugins. These packages were published to the npm registry and are designed to exploit Redis for remote code execution (RCE), facilitate credential theft, and establish persistent command-and-control (C2) access. The attack utilized four sock-puppet npm accounts: umarbek1233, kekylf12, tikeqemif26, and umar_bektembiev1. Developers using Strapi for application development are the primary targets of this campaign. The malicious packages pose a significant risk by enabling attackers to execute arbitrary code on affected systems. The full scope of the impact is still being assessed, but the presence of these packages in the npm registry raises concerns about the security of open-source software supply chains. Security professionals are urged to review their dependencies and ensure they are not using these malicious packages.

Key Points: • 36 malicious npm packages disguised as Strapi plugins were identified. • The attack enables Redis remote code execution and credential harvesting. • Developers using Strapi are primarily affected by this supply chain attack.

ThreatCluster AI How this analysis works

Timeline

2026-04-06
Discovery of 36 malicious npm packages targeting Strapi
2026-04-06
Identification of four sock-puppet npm accounts used in the attack
Recent
Ongoing assessment of the impact and scope of the attack

Community

Browse all →

Tracked Entities in This Story