Story perspectives
Supply Chain Attack Targets Strapi Users with Malicious Plugins
4/6/2026
1 of 1
Story summary
- SafeDep, a cybersecurity firm, reports a supply chain attack in the Strapi ecosystem.
- The attack involves 36 malicious NPM packages masquerading as Strapi CMS plugins.
- The packages deliver payloads that can exploit Redis and PostgreSQL, harvest credentials, and deploy reverse shells.
- Four accounts uploaded the packages, and SafeDep urges affected users to rotate all credentials.
- The attack appears tailored for Strapi users and centers on the cryptocurrency payment gateway Guardarian.
