Cybersecurity researchers have discovered 36 malicious npm packages masquerading as Strapi CMS but containing different payloads to exploit Redis and PostgreSQL, install reverse shells, collect credentials, and install persistent implants. SafeDep uncovers a coordinated attack on the npm registry targeting developers and CI/CD.

All detected npm packages follow the same naming convention, starting with “strapi-plugin-” and continuing with phrases like “cron”, “database” or “server” to mislead developers. It is important to note that the official Strapi plugins are scoped under “@strapi/“.
Each package contains only three files (package.json, index.js, postinstall.js), has no description, repository, or homepage, and uses version 3.6.8 to appear as a mature Strapi v3 community plugin.
See also: Malicious Laravel Packages on Packagist Install RAT
The packages were uploaded by four fake accounts: “umarbek1233“, “kekylf12“, “tikeqemif26“, and “umar_bektembiev1“ over a period of 13 hours:
- strapi-plugin-cron
- strapi-plugin-config
- strapi-plugin-server
- strapi-plugin-database
- strapi-plugin-core
- strapi-plugin-hooks
- strapi-plugin-monitor
- strapi-plugin-events
- strapi-plugin-logger
- strapi-plugin-health
- strapi-plugin-sync
- strapi-plugin-seed
- strapi-plugin-locale
- strapi-plugin-form
- strapi-plugin-notify
- strapi-plugin-api
- strapi-plugin-sitemap-gen
- strapi-plugin-nordica-tools
- strapi-plugin-nordica-sync
- strapi-plugin-nordica-cms
- strapi-plugin-nordica-api
- strapi-plugin-nordica-recon
- strapi-plugin-nordica-stage
- strapi-plugin-nordica-vhost
- strapi-plugin-nordica-deep
- strapi-plugin-nordica-lite
- strapi-plugin-nordica
- strapi-plugin-finseven
- strapi-plugin-hextest
- strapi-plugin-cms-tools
- strapi-plugin-content-sync
- strapi-plugin-debug-tools
- strapi-plugin-health-check
- strapi-plugin-guardarian-ext
- strapi-plugin-advanced-uuid
- strapi-plugin-blurhash

Technical details of npm packages and attack mechanism
Analysis of npm packages reveals that the malicious code is embedded in the postinstall script hook , which is executed during “ npm install ” without requiring user interaction. It runs with the same privileges as the installing user, which means it abuses root access in CI/CD environments and Docker containers . This technique is particularly dangerous as it allows for the automatic execution of malicious code without the developer’s knowledge.
See also: Ghost Campaign: 7 malicious npm packages steal crypto wallets
According to The Hacker News, the evolution of the payloads distributed as part of the campaign includes eight different stages.
First, they infect a locally accessible Redis instance for remote code execution by inserting a crontab entry that downloads and executes a shell script from a remote server every minute. The shell script writes a PHP web shell and Node.js reverse shell via SSH to the public uploads directory of Strapi. In addition, it attempts to scan the disk for secrets such as Elasticsearch and cryptocurrency wallet seed phrases. Finally, it exports a Guardarian API module.
In the next stage, the attack combines the Redis with Docker container escape to write shell payloads to the host outside the container. It also launches a direct Python reverse shell on port 4444 and writes a reverse shell trigger to the application's node_modules directory via Redis.
Then, a reverse shell, a shell downloader via Redis, and the resulting file is executed.
This is followed by a system scan for environment variables and PostgreSQL database connection strings.
An extensive credential harvester and reconnaissance payload begin collecting environment dumps, Strapi configurations, Redis database executing INFO, DBSIZE, and KEYS commands, network topology mapping, Docker/Kubernetes secrets, cryptographic keys, and cryptocurrency wallet files.

This is followed by a PostgreSQL database exploit by connecting to the target’s PostgreSQL database (via hard-coded credentials and querying Strapi-specific tables for secrets). It also records corresponding cryptocurrency-related patterns (e.g. wallet, transaction, deposit, withdrawal, hot, cold, and balance) and attempts to connect to six Guardarian. This indicates that the threat actor already has the data, which was obtained either through a previous breach or through other means.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In the seventh stage, a persistent implant designed to maintain remote access to a specific hostname (“prod-strapi”) is developed.
Finally, credentials are stolen via hard-coded paths and a persistent reverse shell.
See also: North Koreans published 26 malicious npm packages for RAT distribution
This discovery highlights the ongoing threat of supply chain attacks in the npm ecosystem. Developers should be extra careful when installing packages, especially those that lack adequate documentation or come from unknown sources. Using tools like npm audit and regularly inspecting dependencies can help prevent such attacks.
