Objective
Establish persistent C2 and exfiltrate databases from Strapi deployments.
Packages
- npm strapi-plugin-cronattributed-to
- npm strapi-plugin-configattributed-to
- npm strapi-plugin-serverattributed-to
- npm strapi-plugin-databaseattributed-to
- npm strapi-plugin-coreattributed-to
- npm strapi-plugin-hooksattributed-to
- npm strapi-plugin-monitorattributed-to
- npm strapi-plugin-eventsattributed-to
- npm strapi-plugin-loggerattributed-to
- npm strapi-plugin-healthattributed-to
- npm strapi-plugin-syncattributed-to
- npm strapi-plugin-seedattributed-to
- npm strapi-plugin-localeattributed-to
- npm strapi-plugin-formattributed-to
- npm strapi-plugin-notifyattributed-to
- npm strapi-plugin-apiattributed-to
- npm strapi-plugin-sitemap-genattributed-to
- npm strapi-plugin-nordica-toolsattributed-to
- npm strapi-plugin-nordica-syncattributed-to
- npm strapi-plugin-nordica-cmsattributed-to
- npm strapi-plugin-nordica-apiattributed-to
- npm strapi-plugin-nordica-reconattributed-to
- npm strapi-plugin-nordica-stageattributed-to
- npm strapi-plugin-nordica-vhostattributed-to
- npm strapi-plugin-nordica-deepattributed-to
- npm strapi-plugin-nordica-liteattributed-to
- npm strapi-plugin-nordicaattributed-to
- npm strapi-plugin-finsevenattributed-to
- npm strapi-plugin-hextestattributed-to
- npm strapi-plugin-cms-toolsattributed-to
- npm strapi-plugin-content-syncattributed-to
- npm strapi-plugin-debug-toolsattributed-to
- npm strapi-plugin-health-checkattributed-to
- npm strapi-plugin-guardarian-extattributed-to
- npm strapi-plugin-advanced-uuidattributed-to
- npm strapi-plugin-blurhashattributed-to
Indicators
Techniques
- ttp T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Toolsuses
- ttp T1059.007 Command and Scripting Interpreter: JavaScriptuses
- ttp T1036 Masqueradinguses
- ttp T1105 Ingress Tool Transferuses
- ttp T1071.001 Application Layer Protocol: Web Protocolsuses
- ttp T1546 Event Triggered Executionuses
