14 Trojanized npm Packages Distribute RedC2 4.0 Linux Backdoor with AI-Driven C2 Functionality

Published:

spot_img

Cybersecurity researchers have identified a series of trojanized npm packages that disguise themselves as calendar and streak utilities while delivering an artificial intelligence (AI)-powered Linux implant known as RedC2 4.0. According to a report by Trend Micro’s enterprise cybersecurity division, TrendAI, these malicious packages execute their payloads without requiring an install hook, making them particularly stealthy.

The identified packages include:

  • streak-metrics-math@1.0.0,1.0.1
  • kit-map-vim@1.0.0
  • streak-map-cache@1.0.0
  • streak-map-kit@1.0.0
  • map-streak-kit@1.0.0
  • streak-cache-map@1.0.0
  • streak-calc-metrics@1.0.0
  • streak-calc-math@1.0.0
  • streak-math-abz@1.0.0
  • streak-metricsaz@1.0.0
  • streak-math-metrics@1.0.0
  • streak-metricazbd@1.0.0
  • streak-metricsazb@1.0.0
  • streak-kit-map@1.0.0

While these packages provide legitimate functionality, they also contain code that drops a Linux backdoor, masquerading as a native math accelerator. The backdoor, referred to as the RedShell Linux beacon, communicates with remote servers to facilitate post-exploitation activities.

RedC2 4.0 is marketed on cybercrime forums as a versatile toolkit for various operating systems, including Windows, macOS, and Linux, offering capabilities such as surveillance and credential theft. The framework has been under active development, with previous versions released in early 2026 and earlier.

Notably, the RedC2 framework includes an AI-driven component called Red Agent, which allows operators to execute complex tasks using natural language commands. This integration of AI into the command-and-control framework represents a significant evolution in cybercrime tools, lowering the barrier for less experienced operators to conduct sophisticated intrusions.

The findings highlight the ongoing threat posed by malicious npm packages and the increasing sophistication of cybercriminal tools. As these developments unfold, organizations are urged to remain vigilant and implement robust security measures to protect against such threats.

For further details, refer to the report by The Hacker News.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

spot_img

Related articles

Recent articles

First Documented Android Malware Targets Automotive Head Units for Ad Fraud

In June 2026, researchers monitoring Android threats uncovered a novel piece of malware that specifically targets automotive head units. This malware, which installs like...

VAD Technologies Highlights Path for AI-Ready Channel Partners in the Middle East

VAD Technologies Charts a Course for AI-Ready Channel Partners in the Middle East VAD Technologies is emphasizing the critical role of channel partners in navigating...

Lawmakers Request GAO Investigation into CISA Staffing Cuts and Impact on Cybersecurity Operations

Members of Congress are urging a government watchdog to investigate the impact of staffing cuts at the Cybersecurity and Infrastructure Security Agency (CISA) on...

China’s Volt Typhoon Hacking Group Prepares to Disrupt U.S. Civilian Infrastructure, Warns Experts

Recent discussions among insurance executives have highlighted a concerning scenario: a coordinated Chinese cyberattack could potentially incapacitate 5,000 water utilities across the United States...