36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants

2026-04-05T13:24:09Z3e5ba9a7166b7163edca3fda220f7b63dac231161bfecd45a3499baad96e165a
AxiosCVE-2025-55182CVE-2026-20093CVE-2026-35616CVE-2026-5281ChromeCiscoFortiClient EMSFortinetNext.jsPHPPlugX','OAuth-phishing','SparkCat','mobile-malware','Drift','solPostgreSQLRedisStrapiTA416UNC1069cookie-controlcronmalicious-packagesnpmpersistencesocial-engineeringsupply-chainweb-shells

What happened

Multiple high-impact security incidents and active-exploitation vulnerabilities were reported: researchers found 36 malicious npm packages masquerading as Strapi plugins that deploy Redis/PostgreSQL exploits, reverse shells and persistent implants; Fortinet released an out-of-band patch for an actively exploited pre-auth privilege-escalation bug (CVE-2026-35616); Google/others attributed the Axios npm supply-chain compromise to North Korean UNC1069 following targeted social engineering; a Chrome zero-day in Dawn (CVE-2026-5281) is under active exploitation and patched; Cisco patched a critical

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
3e5ba9a7166b7163edca3fda220f7b63dac231161bfecd45a3499baad96e165a
Enrichment time
2026-04-05T13:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.