
Technology
36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants
April 5, 2026
The Hacker News
Scroll
Cybersecurity researchers have discovered 36 malicious packages in the npm registry that are disguised as Strapi CMS plugins but come with different payloads to facilitate Redis and PostgreSQL exploitation, deploy reverse shells, harvest credentials, and drop a persistent implant. Every package contains three files (package.json, index.js, postinstall.js), has no description, repository,

The Hacker News
Coverage and analysis from United States of America. All insights are generated by our AI narrative analysis engine.
United States of America
Bias: Unknown