Diamond Member ThaHaka 0 Posted April 5 Diamond Member Share Posted April 5 This is the hidden content, please Sign In or Sign Up Cybersecurity researchers have discovered 36 malicious packages in the npm registry that are disguised as Strapi CMS plugins but come with different payloads to facilitate Redis and PostgreSQL exploitation, deploy reverse shells, harvest credentials, and drop a persistent implant. "Every package contains three files (package.json, index.js, postinstall.js), has no description, repository, This is the hidden content, please Sign In or Sign Up 0 Quote Link to comment https://hopzone.eu/forums/topic/307789-h4ckn3ws36-malicious-npm-packages-exploited-redis-postgresql-to-deploy-persistent-implants/ Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.