Strapi Plugin C2 Campaign
36 npm packages impersonating Strapi plugins that deploy Redis RCE, steal databases and maintain persistent command and control.
discovered 2026-04-03
Objective
Establish persistent C2 and exfiltrate databases from Strapi deployments.
Packages
- npmstrapi-plugin-cronattributed-to
- npmstrapi-plugin-configattributed-to
- npmstrapi-plugin-serverattributed-to
- npmstrapi-plugin-databaseattributed-to
- npmstrapi-plugin-coreattributed-to
- npmstrapi-plugin-hooksattributed-to
- npmstrapi-plugin-monitorattributed-to
- npmstrapi-plugin-eventsattributed-to
- npmstrapi-plugin-loggerattributed-to
- npmstrapi-plugin-healthattributed-to
- npmstrapi-plugin-syncattributed-to
- npmstrapi-plugin-seedattributed-to
- npmstrapi-plugin-localeattributed-to
- npmstrapi-plugin-formattributed-to
- npmstrapi-plugin-notifyattributed-to
- npmstrapi-plugin-apiattributed-to
- npmstrapi-plugin-sitemap-genattributed-to
- npmstrapi-plugin-nordica-toolsattributed-to
- npmstrapi-plugin-nordica-syncattributed-to
- npmstrapi-plugin-nordica-cmsattributed-to
- npmstrapi-plugin-nordica-apiattributed-to
- npmstrapi-plugin-nordica-reconattributed-to
- npmstrapi-plugin-nordica-stageattributed-to
- npmstrapi-plugin-nordica-vhostattributed-to
- npmstrapi-plugin-nordica-deepattributed-to
- npmstrapi-plugin-nordica-liteattributed-to
- npmstrapi-plugin-nordicaattributed-to
- npmstrapi-plugin-finsevenattributed-to
- npmstrapi-plugin-hextestattributed-to
- npmstrapi-plugin-cms-toolsattributed-to
- npmstrapi-plugin-content-syncattributed-to
- npmstrapi-plugin-debug-toolsattributed-to
- npmstrapi-plugin-health-checkattributed-to
- npmstrapi-plugin-guardarian-extattributed-to
- npmstrapi-plugin-advanced-uuidattributed-to
- npmstrapi-plugin-blurhashattributed-to
Indicators
Techniques
- ttpT1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Toolsuses
- ttpT1059.007 Command and Scripting Interpreter: JavaScriptuses
- ttpT1036 Masquerading: package impersonation and typosquattinguses
- ttpT1105 Ingress Tool Transferuses
- ttpT1071.001 Application Layer Protocol: Web Protocolsuses
- ttpT1546 Event Triggered Executionuses
