36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants
2026-04-05T13:24:09Z•3e5ba9a7166b7163edca3fda220f7b63dac231161bfecd45a3499baad96e165a
AxiosCVE-2025-55182CVE-2026-20093CVE-2026-35616CVE-2026-5281ChromeCiscoFortiClient EMSFortinetNext.jsPHPPlugX','OAuth-phishing','SparkCat','mobile-malware','Drift','solPostgreSQLRedisStrapiTA416UNC1069cookie-controlcronmalicious-packagesnpmpersistencesocial-engineeringsupply-chainweb-shells
What happened
Multiple high-impact security incidents and active-exploitation vulnerabilities were reported: researchers found 36 malicious npm packages masquerading as Strapi plugins that deploy Redis/PostgreSQL exploits, reverse shells and persistent implants; Fortinet released an out-of-band patch for an actively exploited pre-auth privilege-escalation bug (CVE-2026-35616); Google/others attributed the Axios npm supply-chain compromise to North Korean UNC1069 following targeted social engineering; a Chrome zero-day in Dawn (CVE-2026-5281) is under active exploitation and patched; Cisco patched a critical
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 3e5ba9a7166b7163edca3fda220f7b63dac231161bfecd45a3499baad96e165a
- Enrichment time
- 2026-04-05T13:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.