- Malicious Strapi NPM packages (36 total)Campaign targeting Guardarian cryptocurrency payment gateway via NPM package poisoning
- Redis RCE payloadInjects crontab entries, deploys PHP webshells, Node.js reverse shells, SSH key injection
- Docker escape payloadExploits overlay filesystem, writes shells to host, launches reverse shells, exfiltrates credentials
- Credential harvesting payloadTargets PostgreSQL, Elasticsearch, wallet files, Strapi configurations, persistent implants
ThreatNoir Afternoon Brief — April 6
Afternoon Review in IT Security — April 6, 2026
The security landscape continues to face mounting pressure from sophisticated threat actors exploiting supply chain vulnerabilities, conducting extended social engineering campaigns, and targeting critical infrastructure. Today's briefing covers malicious package distribution, multi-million-dollar cryptocurrency theft, coordinated attacks on open-source maintainers, and emergency patching efforts for critical zero-days.
Guardarian Users Targeted With Malicious Strapi NPM Packages
Threat actors have published 36 malicious NPM packages designed to impersonate Strapi plugins, targeting users of the Guardarian cryptocurrency gateway. These packages contain multiple attack payloads including credential harvesting mechanisms, Docker escape exploits, Redis remote code execution capabilities, and shell execution functionality. The distribution of these packages demonstrates the ongoing risk posed by supply chain attacks targeting the cryptocurrency and development communities through popular package repositories.
Source: SecurityWeek
North Korean Hackers Pose as Trading Firm to Steal $285M from Drift
A North Korean threat actor group designated UNC4736 conducted an extended social engineering operation against Drift Protocol, maintaining a false trading firm persona for six months before executing a theft of $285 million in cryptocurrency. The prolonged engagement allowed the attackers to build trust and bypass security measures without triggering suspicion. This campaign highlights the effectiveness of patient, long-term social engineering tactics against even security-conscious cryptocurrency platforms.
Source: Hackread
North Korean Hackers Target High-Profile Node.js Maintainers
The same threat actor responsible for the Axios supply chain attack has expanded its targeting to other prominent Node.js package maintainers through sophisticated social engineering campaigns. The attackers are employing remote access trojans as part of their arsenal to compromise these critical open-source developers. This coordinated effort against the Node.js ecosystem represents a significant threat to the integrity of widely-used software dependencies.
Source: SecurityWeek
Fortinet Rushes Emergency Fixes for Exploited Zero-Day
Fortinet has released emergency patches addressing critical improper access control vulnerabilities in FortiClient EMS that allow unauthenticated attackers to execute arbitrary code remotely. The affected vulnerabilities are tracked as CVE-2026-21643 and CVE-2026-35616. The rapid deployment of these fixes reflects the severity of the zero-day exploitation and the immediate risk posed to organizations relying on Fortinet's endpoint management solutions.
Source: SecurityWeek
Today's threat landscape demonstrates a coordinated assault across multiple attack vectors, from package repository poisoning to extended social engineering operations and active zero-day exploitation. Organizations should prioritize supply chain security assessments, implement enhanced verification procedures for third-party relationships, and maintain aggressive patching schedules for critical infrastructure components.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- RAT (Remote Access Trojan)Deployed via fake update in social engineering attack against Axios maintainer
- Critical improper access control vulnerability in FortiClient EMS allowing unauthenticated RCE
- SQL injection vulnerability in FortiClient EMS exploited for over a week