36 fake Strapi plugins on npm deploy persistent implants
Four sock-puppet npm accounts (umarbek1233, kekylf12, tikeqemif26, umar_bektembiev1) uploaded 36 packages over a ~13-hour window impersonating Strapi CMS plugins. Payload evolution moved through 8 variants targeting Redis RCE with cron injection, Docker container escapes, PostgreSQL exploitation on hosts named prod-strapi, Python reverse shells on port 4444, and SSH-key backdoors.
Versions named here: