Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Guardarian Users Targeted With Malicious Strapi NPM Packages
    Cybersecurity

    Guardarian Users Targeted With Malicious Strapi NPM Packages

    adminBy adminApril 6, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Developer security vulnerability
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A threat actor has targeted the Strapi ecosystem in a fresh supply chain attack involving 36 malicious NPM packages, according to supply chain security firm SafeDep.

    An open source headless CMS built on Node.js, Strapi allows developers to create websites and mobile applications and generate APIs, enabling them to use their favorite tools and frameworks.

    On Friday, SafeDep warned that 36 NPM packages published across four accounts as part of a single campaign are delivering various malicious payloads capable of Redis code execution, Docker container escape, credential harvesting, and reverse shell deployment.

    One of the payloads exploits Redis instances to inject crontab entries, deploy PHP webshells and Node.js reverse shells, inject SSH keys, and exfiltrate a Guardarian API module.

    Another payload was designed to escape Docker containers via overlay filesystem discovery, write shells to host directories, launch a reverse shell, and read Elasticsearch and wallet credentials.

    Other payloads were observed deploying reverse shells, harvesting credentials, targeting PostgreSQL databases, searching for wallet/key files, exfiltrating Strapi configurations, and deploying persistent implants.

    Advertisement. Scroll to continue reading.

    The campaign, SafeDep says, is targeting the cryptocurrency payment gateway Guardarian, based on direct probing of databases associated with it, the use of a Guardarian API module, and the targeting of specific wallet files.

    “The eight payloads show a clear narrative: the attacker started aggressive (Redis RCE, Docker escape), found those approaches weren’t working, pivoted to reconnaissance and data collection, used hardcoded credentials for direct database access, and finally settled on persistent access with targeted credential theft,” the cybersecurity firm notes.

    SafeDep assesses that the campaign was tailored for Strapi users, based on the plugin naming scheme, file paths for configuration directories, environmental variable paths for Docker images, the targeting of Redis instances used as Strapi cache backends, and the focus on Linux systems.

    Users who installed the malicious packages are advised to rotate all credentials, including database passwords, API keys, JWT secrets, and other secrets stored on their systems.

    Related: European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack

    Related: Telnyx Targeted in Growing TeamPCP Supply Chain Attack

    Related: NPM Package With 56,000 Downloads Steals WhatsApp Credentials, Data

    Related: Mercor Hit by LiteLLM Supply Chain Attack

    Guardarian Malicious npm Packages Strapi targeted Users
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleHow to produce content that naturally builds AEO clout
    Next Article AI for IT stalls as network complexity rises
    admin
    • Website

    Related Posts

    OpenAI Widens Access to Cybersecurity Model After Anthropic’s Mythos Reveal

    April 16, 2026

    Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808)

    April 16, 2026

    Cisco says critical Webex Services flaw requires customer action

    April 16, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    OpenAI Widens Access to Cybersecurity Model After Anthropic’s Mythos Reveal

    April 16, 2026

    Gemini blocked more than 99% of bad ads before they ran in 2025

    April 16, 2026

    I tested the Moto G Stylus 2026, and it’s finally starting to feel like an affordable alternative to the Galaxy S26 Ultra, but the price tag makes it a tougher sell

    April 16, 2026

    IBM unveils security services for thwarting agentic attacks, automating threat assessment

    April 16, 2026
    Categories
    • Blogging (63)
    • Cybersecurity (1,346)
    • Privacy & Online Earning (168)
    • SEO & Digital Marketing (826)
    • Tech Tools & Mobile / Apps (1,611)
    • WiFi / Internet & Networking (226)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    OpenAI Widens Access to Cybersecurity Model After Anthropic’s Mythos Reveal

    April 16, 2026

    Gemini blocked more than 99% of bad ads before they ran in 2025

    April 16, 2026

    I tested the Moto G Stylus 2026, and it’s finally starting to feel like an affordable alternative to the Galaxy S26 Ultra, but the price tag makes it a tougher sell

    April 16, 2026
    Most Popular
    • OpenAI Widens Access to Cybersecurity Model After Anthropic’s Mythos Reveal
    • Gemini blocked more than 99% of bad ads before they ran in 2025
    • I tested the Moto G Stylus 2026, and it’s finally starting to feel like an affordable alternative to the Galaxy S26 Ultra, but the price tag makes it a tougher sell
    • IBM unveils security services for thwarting agentic attacks, automating threat assessment
    • What Is Answer Engine Optimization? And How to Do It
    • Who goes there? Your Ring doorbell can now recognise up to 50 familiar faces, and let you know if a caller is a friend or a stranger
    • COSMIC desktop surprised me, because it’s the Linux DE I’ve been waiting for
    • Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808)
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.