Cybersecurity researchers have identified a series of trojanized npm packages that disguise themselves as calendar and streak utilities while delivering an artificial intelligence (AI)-powered Linux implant known as RedC2 4.0. According to a report by Trend Micro’s enterprise cybersecurity division, TrendAI, these malicious packages execute their payloads without requiring an install hook, making them particularly stealthy.
The identified packages include:
- streak-metrics-math@1.0.0,1.0.1
- kit-map-vim@1.0.0
- streak-map-cache@1.0.0
- streak-map-kit@1.0.0
- map-streak-kit@1.0.0
- streak-cache-map@1.0.0
- streak-calc-metrics@1.0.0
- streak-calc-math@1.0.0
- streak-math-abz@1.0.0
- streak-metricsaz@1.0.0
- streak-math-metrics@1.0.0
- streak-metricazbd@1.0.0
- streak-metricsazb@1.0.0
- streak-kit-map@1.0.0
While these packages provide legitimate functionality, they also contain code that drops a Linux backdoor, masquerading as a native math accelerator. The backdoor, referred to as the RedShell Linux beacon, communicates with remote servers to facilitate post-exploitation activities.
RedC2 4.0 is marketed on cybercrime forums as a versatile toolkit for various operating systems, including Windows, macOS, and Linux, offering capabilities such as surveillance and credential theft. The framework has been under active development, with previous versions released in early 2026 and earlier.
Notably, the RedC2 framework includes an AI-driven component called Red Agent, which allows operators to execute complex tasks using natural language commands. This integration of AI into the command-and-control framework represents a significant evolution in cybercrime tools, lowering the barrier for less experienced operators to conduct sophisticated intrusions.
The findings highlight the ongoing threat posed by malicious npm packages and the increasing sophistication of cybercriminal tools. As these developments unfold, organizations are urged to remain vigilant and implement robust security measures to protect against such threats.
For further details, refer to the report by The Hacker News.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.



