HomeSecurity36 malicious npm packages exploit Redis and PostgreSQL

36 malicious npm packages exploit Redis and PostgreSQL

Cybersecurity researchers have discovered 36 malicious npm packages masquerading as Strapi CMS but containing different payloads to exploit Redis and PostgreSQL, install reverse shells, collect credentials, and install persistent implants. SafeDep uncovers a coordinated attack on the npm registry targeting developers and CI/CD.

npm Redis and PostgreSQL

All detected npm packages follow the same naming convention, starting with “strapi-plugin-” and continuing with phrases like “cron”, “database” or “server” to mislead developers. It is important to note that the official Strapi plugins are scoped under “@strapi/“.

Each package contains only three files (package.json, index.js, postinstall.js), has no description, repository, or homepage, and uses version 3.6.8 to appear as a mature Strapi v3 community plugin.

See also: Malicious Laravel Packages on Packagist Install RAT

The packages were uploaded by four fake accounts: “umarbek1233“, “kekylf12“, “tikeqemif26“, and “umar_bektembiev1“ over a period of 13 hours:

  • strapi-plugin-cron
  • strapi-plugin-config
  • strapi-plugin-server
  • strapi-plugin-database
  • strapi-plugin-core
  • strapi-plugin-hooks
  • strapi-plugin-monitor
  • strapi-plugin-events
  • strapi-plugin-logger
  • strapi-plugin-health
  • strapi-plugin-sync
  • strapi-plugin-seed
  • strapi-plugin-locale
  • strapi-plugin-form
  • strapi-plugin-notify
  • strapi-plugin-api
  • strapi-plugin-sitemap-gen
  • strapi-plugin-nordica-tools
  • strapi-plugin-nordica-sync
  • strapi-plugin-nordica-cms
  • strapi-plugin-nordica-api
  • strapi-plugin-nordica-recon
  • strapi-plugin-nordica-stage
  • strapi-plugin-nordica-vhost
  • strapi-plugin-nordica-deep
  • strapi-plugin-nordica-lite
  • strapi-plugin-nordica
  • strapi-plugin-finseven
  • strapi-plugin-hextest
  • strapi-plugin-cms-tools
  • strapi-plugin-content-sync
  • strapi-plugin-debug-tools
  • strapi-plugin-health-check
  • strapi-plugin-guardarian-ext
  • strapi-plugin-advanced-uuid
  • strapi-plugin-blurhash 
36 malicious npm packages exploit Redis and PostgreSQL

Technical details of npm packages and attack mechanism

Analysis of npm packages reveals that the malicious code is embedded in the postinstall script hook , which is executed during “ npm install ” without requiring user interaction. It runs with the same privileges as the installing user, which means it abuses root access in CI/CD environments and Docker containers . This technique is particularly dangerous as it allows for the automatic execution of malicious code without the developer’s knowledge.

See also: Ghost Campaign: 7 malicious npm packages steal crypto wallets

According to The Hacker News, the evolution of the payloads distributed as part of the campaign includes eight different stages.

First, they infect a locally accessible Redis instance for remote code execution by inserting a crontab entry that downloads and executes a shell script from a remote server every minute. The shell script writes a PHP web shell and Node.js reverse shell via SSH to the public uploads directory of Strapi. In addition, it attempts to scan the disk for secrets such as Elasticsearch and cryptocurrency wallet seed phrases. Finally, it exports a Guardarian API module.

In the next stage, the attack combines the Redis with Docker container escape to write shell payloads to the host outside the container. It also launches a direct Python reverse shell on port 4444 and writes a reverse shell trigger to the application's node_modules directory via Redis.

Then, a reverse shell, a shell downloader via Redis, and the resulting file is executed.

This is followed by a system scan for environment variables and PostgreSQL database connection strings.

An extensive credential harvester and reconnaissance payload begin collecting environment dumps, Strapi configurations, Redis database executing INFO, DBSIZE, and KEYS commands, network topology mapping, Docker/Kubernetes secrets, cryptographic keys, and cryptocurrency wallet files.

Malicious npm packages targeting Redis and PostgreSQL databases

This is followed by a PostgreSQL database exploit by connecting to the target’s PostgreSQL database (via hard-coded credentials and querying Strapi-specific tables for secrets). It also records corresponding cryptocurrency-related patterns (e.g. wallet, transaction, deposit, withdrawal, hot, cold, and balance) and attempts to connect to six Guardarian. This indicates that the threat actor already has the data, which was obtained either through a previous breach or through other means.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

In the seventh stage, a persistent implant designed to maintain remote access to a specific hostname (“prod-strapi”) is developed.

Finally, credentials are stolen via hard-coded paths and a persistent reverse shell.

See also: North Koreans published 26 malicious npm packages for RAT distribution

This discovery highlights the ongoing threat of supply chain attacks in the npm ecosystem. Developers should be extra careful when installing packages, especially those that lack adequate documentation or come from unknown sources. Using tools like npm audit and regularly inspecting dependencies can help prevent such attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS