[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fz_5sKzs6wEwb7TQCiyRDPC5qbkuTfyDYMJkTCNvS1v4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"2e3df4d9-4048-4b88-9ec5-e43a58bb9535","malicious-npm-packages-target-cryptocurrency-gateway-users","48fb57ba-8f90-4b76-af05-1e74e08edbca","Malicious NPM Packages Target Cryptocurrency Gateway Users","Threat actors successfully published 36 malicious NPM packages disguised as legitimate Strapi plugins, specifically targeting Guardarian cryptocurrency gateway users. The attack demonstrates sophisticated supply chain compromise techniques, delivering multiple payloads including credential theft, container escape capabilities, and persistent backdoors. When initial aggressive attacks were detected, the attackers adapted their strategy to focus on reconnaissance and targeted credential harvesting, showing the evolving nature of supply chain threats.","**Immediate actions:**\n- Audit all NPM packages in current projects and verify authenticity of Strapi plugins\n- Implement package scanning tools to detect malicious dependencies before deployment\n- Review systems for indicators of compromise including unusual Redis activity or container behavior\n\n**Long-term improvements:**\n- Establish approved package repositories and require security review for new dependencies\n- Implement dependency pinning and automated vulnerability scanning for all third-party packages\n- Create isolated development environments to limit blast radius of compromised packages\n\n**Detection measures:**\n- Monitor package installation activities and flag suspicious or newly published packages\n- Deploy behavioral analytics to detect unusual credential access patterns or container escape attempts\n- Establish alerting for unauthorized network connections from development and production environments",[12,13,14,15,16],"NIST SP 800-161","CIS Control 2","CIS Control 11","OWASP Top 10 A06","SSDF PW.4.1","published","2026-04-06T12:08:08.119357+00:00","2026-04-06T12:08:07.825+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fwww.securityweek.com\u002Fguardarian-users-targeted-with-malicious-strapi-npm-packages\u002F","guardarian-users-targeted-with-malicious-strapi-npm-packages","Guardarian Users Targeted With Malicious Strapi NPM Packages",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":32,"name":33,"slug":34,"description":35,"color":36},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[38],{"id":39,"date":40,"edition":41,"title":42,"audio_url":43},"5e08eadf-931e-4311-b6dd-cfa20a0e8447","2026-04-06","afternoon","ThreatNoir Afternoon Brief — April 6","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-04-06\u002Fthreatnoir-afternoon-brief-2026-04-06.mp3"]