Strapi plugins exploit Redis and PostgreSQL via postinstall scripts, enabling persistent access and data theft.
A fake $TEMU crypto airdrop uses the ClickFix trick to make victims run malware themselves and quietly installs a remote-access backdoor.