Strapi plugins exploit Redis and PostgreSQL via postinstall scripts, enabling persistent access and data theft.
North Korean hackers published backdoored versions of the Axios NPM package using a compromised long-lived access token.
A threat actor has used 36 malicious NPM packages posing as Strapi plugins to distribute malware targeting Redis, Docker, and ...