14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

Executive Summary

Researchers found 14 trojanized npm packages that appear as calendar and streak utilities but embed an AI‑powered Linux backdoor, RedC2 4.0. When loaded, the module makes the bundled binary executable and launches it as a detached background process, enabling stealthy command‑and‑control.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-08-21T18:53:00+00:00 - Category: threat-intel

Original Description: Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. "When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process," TrendAI, Trend Micro's

"The conditions of conquest are always easy. We have but to toil awhile, endure awhile, believe always, and never turn back."

— Seneca
Source: The Hacker News