HackMyIP
← Back to News
2026-08-21 The Hacker News

Trojanized npm Packages Deliver RedC2 4.0 Linux Backdoor in Supply Chain Attack

Supply ChainMalwareAI Threats

Cybersecurity researchers at TrendAI, the enterprise security arm of Trend Micro, have uncovered 14 trojanized npm packages that masquerade as legitimate calendar, streak-tracking, and math utility libraries while secretly deploying an AI-powered Linux implant known as RedC2 4.0. The malicious packages—including streak-metrics-math@1.0.0, streak-metrics-math@1.0.1, kit-map-vim@1.0.0, streak-map-cache@1.0.0, and ten others using similar naming conventions—appear fully functional on the surface. Hidden beneath their date-helper facade, however, is a trojan loader in dist/index.mjs that locates a bundled binary, marks it executable, and launches it as a detached background process. Crucially, the payload requires no install hook; a single import anywhere in the dependency graph, including transitive dependencies, is sufficient to trigger execution.

The embedded payload is the RedShell Linux beacon for RedC2 4.0, disguised as a native math accelerator under filenames such as math-core.bin, calc-math.dat, calc-mapping.bin, and calc.bin, stored in either dist/ or dist/internal/. RedC2 4.0 is marketed on Hack Forums by a threat actor using the handle "MarlboroMan" as a cross-platform C2 framework supporting Windows, macOS, and Linux, with features spanning terminal access, file transfer, staged payload delivery, credential theft, in-memory execution of BOFs and .NET assemblies, host-to-host tunneling, and multi-beacon operation. Version 4.0, advertised in early June 2026 as "built for evasion," introduces the AI-assisted Linux beacon and follows version 3.0 (January 2026) and version 2.0 (August 2025), confirming roughly a year of active development.

Once deployed on a compromised host, RedShell communicates with a remote Windows or Linux C2 server to enable post-exploitation activity, including surveillance and data exfiltration. According to Trend Micro researcher Aliakbar Zahravi, the design eliminates traditional detection vectors—there is no exported function call and no install hook, making the malicious activity blend into routine package imports. Organizations relying on open-source JavaScript dependencies should audit their lockfiles for the listed packages and scan for anomalous outbound connections; investigators tracking the associated command-and-control infrastructure can use a WHOIS lookup to examine suspicious domains and a port scanner to identify exposed services on potentially affected hosts. Given the framework's built-in credential theft capabilities, developers and DevOps teams exposed to these packages should also run an email breach checker against corporate accounts to assess potential credential compromise.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →