AUTO-UPDATED

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

Cybersecurity researchers have identified 14 malicious npm packages masquerading as calendar utilities that stealthily install the RedC2 4.0 Linux implant to facilitate unauthorized remote system access and control.

Key Points

  • Trend Micro researchers discovered 14 trojanized npm packages, including streak-metrics-math and kit-map-vim, that function as intended while secretly deploying a Linux backdoor.
  • The malicious packages contain a hidden binary that executes the RedShell Linux beacon, which establishes communication with a remote command-and-control server.
  • RedC2 4.0 is a cross-platform framework marketed for $99.99 that includes "Red Agent," an AI-powered tool allowing operators to execute complex attacks using natural language commands.
  • Once active, the RedShell beacon enables credential theft, file operations, SOCKS5 proxying, and network pivoting on compromised Linux hosts.
  • The framework, developed by a threat actor known as "MarlboroMan," has been under active development since at least August 2025.

Why it Matters

This discovery highlights a growing trend of threat actors leveraging AI-integrated command-and-control frameworks to lower the barrier for executing sophisticated, multi-stage cyberattacks. By embedding these tools within legitimate-looking software dependencies, attackers can compromise development environments and gain persistent access to enterprise systems.
Internet Published by info@thehackernews.com (The Hacker News)
Read original