Cybersecurity researchers have identified 14 malicious npm packages masquerading as calendar utilities that stealthily install the RedC2 4.0 Linux implant to facilitate unauthorized remote system access and control.
Key Points
- Trend Micro researchers discovered 14 trojanized npm packages, including streak-metrics-math and kit-map-vim, that function as intended while secretly deploying a Linux backdoor.
- The malicious packages contain a hidden binary that executes the RedShell Linux beacon, which establishes communication with a remote command-and-control server.
- RedC2 4.0 is a cross-platform framework marketed for $99.99 that includes "Red Agent," an AI-powered tool allowing operators to execute complex attacks using natural language commands.
- Once active, the RedShell beacon enables credential theft, file operations, SOCKS5 proxying, and network pivoting on compromised Linux hosts.
- The framework, developed by a threat actor known as "MarlboroMan," has been under active development since at least August 2025.