securityaffairs.com 4/12/2026, 1:11:26 PM · via preferred

Malicious npm Strapi Packages Spread Redis RCE and Steal Data

Malicious npm Strapi Packages Spread Redis RCE and Steal Data
CyberSIXT Evidence Panel
Primary Source safedep.io
Threat Actor

THE Security Affairs Malware Newsletter Round 92, by Pierluigi Paganini, is described as a collection of the best articles and research on malware in the international landscape, published as the INTERNATIONAL EDITION on 12 April 2026. According to Security Affairs, the roundup brings together a curated set of recent malware-focused pieces from across the sector.

Highlights include Thirty-Six Malicious npm Strapi Packages Deploy Redis RCE, Database Theft, and Persistent C2; GlassWorm evolves with Zig dropper to infect multiple developer tools; and New Lua-based malware “LucidRook” observed in targeted attacks against Taiwanese organisations. The issue also features analyses such as EXPMON detected sophisticated zero-day fingerprinting attack targeting Adobe Reader users and Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities.

Additional items cover topics like ComfyUI servers being repurposed for cryptomining proxy botnets and the broader malware to security research ecosystem, offering a snapshot of current threats and defensive research.

View Primary Source Via securityaffairs.com

Article by CyberSIXT