high Code Vulnerability

36 Malicious npm Packages Exploiting Redis/PostgreSQL

Severityhigh
Statusopen
DateApril 7, 2026
Affectsnpm ecosystem — Redis and PostgreSQL users
Sourcethehackernews.com

Details

36 malicious npm packages discovered in April 2026 that exploit Redis and PostgreSQL connections to deploy persistent implants on developer machines. Part of the broader surge in supply chain attacks targeting package registries.