Strapi plugins exploit Redis and PostgreSQL via postinstall scripts, enabling persistent access and data theft.
M stolen after six-month DPRK social engineering campaign began fall 2025, exposing Drift’s contributors and cloud assets.