Guardarian Users Targeted With Malicious Strapi NPM Packages

2026-04-06T13:24:14Z47bdf485f300f9904c54be64ed5e68a8073225574a663e673c29a61745edd86c
Strapiandroid-rootkitcontainer-escapecredential-harvestingdata-breachforticlient-emsfortinetinfrastructureinsider-threatmobile-securitynexus-listenernorth-koreanpmransomwarereact2shellsharefilesocial-engineeringsupply-chaintrivytrueconfunauthenticated-rcezero-day

What happened

Multiple high-impact incidents and vulnerabilities reported: attackers published 36 malicious NPM packages masquerading as Strapi plugins to execute shells, escape containers and harvest credentials (targeting Guardarian users); a North Korean actor behind the Axios supply-chain compromise is continuing social‑engineering campaigns against high‑profile Node.js maintainers; Fortinet released emergency fixes for an exploited FortiClient EMS improper access control / unauthenticated remote code execution zero‑day; the European Commission confirmed a Trivy supply‑chain–linked breach with >300GB of

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
47bdf485f300f9904c54be64ed5e68a8073225574a663e673c29a61745edd86c
Enrichment time
2026-04-06T13:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.