Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Guardarian Users Targeted With Malicious Strapi NPM Packages
    Cybersecurity

    Guardarian Users Targeted With Malicious Strapi NPM Packages

    adminBy adminApril 6, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Developer security vulnerability
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A threat actor has targeted the Strapi ecosystem in a fresh supply chain attack involving 36 malicious NPM packages, according to supply chain security firm SafeDep.

    An open source headless CMS built on Node.js, Strapi allows developers to create websites and mobile applications and generate APIs, enabling them to use their favorite tools and frameworks.

    On Friday, SafeDep warned that 36 NPM packages published across four accounts as part of a single campaign are delivering various malicious payloads capable of Redis code execution, Docker container escape, credential harvesting, and reverse shell deployment.

    One of the payloads exploits Redis instances to inject crontab entries, deploy PHP webshells and Node.js reverse shells, inject SSH keys, and exfiltrate a Guardarian API module.

    Another payload was designed to escape Docker containers via overlay filesystem discovery, write shells to host directories, launch a reverse shell, and read Elasticsearch and wallet credentials.

    Other payloads were observed deploying reverse shells, harvesting credentials, targeting PostgreSQL databases, searching for wallet/key files, exfiltrating Strapi configurations, and deploying persistent implants.

    Advertisement. Scroll to continue reading.

    The campaign, SafeDep says, is targeting the cryptocurrency payment gateway Guardarian, based on direct probing of databases associated with it, the use of a Guardarian API module, and the targeting of specific wallet files.

    “The eight payloads show a clear narrative: the attacker started aggressive (Redis RCE, Docker escape), found those approaches weren’t working, pivoted to reconnaissance and data collection, used hardcoded credentials for direct database access, and finally settled on persistent access with targeted credential theft,” the cybersecurity firm notes.

    SafeDep assesses that the campaign was tailored for Strapi users, based on the plugin naming scheme, file paths for configuration directories, environmental variable paths for Docker images, the targeting of Redis instances used as Strapi cache backends, and the focus on Linux systems.

    Users who installed the malicious packages are advised to rotate all credentials, including database passwords, API keys, JWT secrets, and other secrets stored on their systems.

    Related: European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack

    Related: Telnyx Targeted in Growing TeamPCP Supply Chain Attack

    Related: NPM Package With 56,000 Downloads Steals WhatsApp Credentials, Data

    Related: Mercor Hit by LiteLLM Supply Chain Attack

    Guardarian Malicious npm Packages Strapi targeted Users
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleHow to produce content that naturally builds AEO clout
    Next Article AI for IT stalls as network complexity rises
    admin
    • Website

    Related Posts

    How Denis Yurchak Built Yadaphone to $17,500 a Month and 20,000 Users in Just Over a Year After the Skype Shut Down

    May 20, 2026

    Encryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewals

    May 20, 2026

    GitHub confirms breach of 3,800 repos via malicious VSCode extension

    May 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    How a ‘client brain’ gives AI the context SEO work needs

    June 2, 2026

    Attackers exploit Palo Alto GlobalProtect flaw days after disclosure

    June 2, 2026

    MIT Research Shows The Shift Reshaping SEO Strategy

    June 2, 2026

    Commerce media expands beyond retail sites with Demand Gen integration

    June 2, 2026
    Categories
    • Blogging (88)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (230)
    • SEO & Digital Marketing (1,337)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (324)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    How a ‘client brain’ gives AI the context SEO work needs

    June 2, 2026

    Attackers exploit Palo Alto GlobalProtect flaw days after disclosure

    June 2, 2026

    MIT Research Shows The Shift Reshaping SEO Strategy

    June 2, 2026
    Most Popular
    • How a ‘client brain’ gives AI the context SEO work needs
    • Attackers exploit Palo Alto GlobalProtect flaw days after disclosure
    • MIT Research Shows The Shift Reshaping SEO Strategy
    • Commerce media expands beyond retail sites with Demand Gen integration
    • The 50 Most-Cited Websites in Perplexity (June 2026)
    • FTC broadens Microsoft probe to cloud, AI, and software bundling
    • Google expands Data Manager API with GMP event ingestion
    • The 50 Most-Cited Websites in Copilot (June 2026)
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.