Strapi is a technology platform tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed April 6, 2026; most recent activity April 6, 2026.
A coordinated supply chain attack has been discovered involving 36 malicious npm packages that impersonate Strapi CMS plugins. These packages were published to the npm registry and are designed to exploit Redis for…
Researchers from SafeDep have identified 36 malicious npm packages disguised as Strapi CMS plugins, which facilitate Redis and PostgreSQL exploitation, reverse shell injections, and credential harvesting. These packages…