14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Executive Summary
Researchers found 14 trojanized npm packages that appear as calendar and streak utilities but embed an AI‑powered Linux backdoor, RedC2 4.0. When loaded, the module makes the bundled binary executable and launches it as a detached background process, enabling stealthy command‑and‑control.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-08-21T18:53:00+00:00 - Category: threat-intel
Original Description: Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. "When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process," TrendAI, Trend Micro's
"The conditions of conquest are always easy. We have but to toil awhile, endure awhile, believe always, and never turn back."
— Seneca