14 Trojanized npm Packages Distribute RedC2 4.0 Linux Backdoor with AI-Driven C2 Functionality

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Cybersecurity researchers have identified a series of trojanized npm packages that disguise themselves as calendar and streak utilities while delivering an artificial intelligence (AI)-powered Linux implant known as RedC2 4.0. According to a report by Trend Micro’s enterprise cybersecurity division, TrendAI, these malicious packages execute their payloads without requiring an install hook, making them particularly stealthy.

The identified packages include:

  • streak-metrics-math@1.0.0,1.0.1
  • kit-map-vim@1.0.0
  • streak-map-cache@1.0.0
  • streak-map-kit@1.0.0
  • map-streak-kit@1.0.0
  • streak-cache-map@1.0.0
  • streak-calc-metrics@1.0.0
  • streak-calc-math@1.0.0
  • streak-math-abz@1.0.0
  • streak-metricsaz@1.0.0
  • streak-math-metrics@1.0.0
  • streak-metricazbd@1.0.0
  • streak-metricsazb@1.0.0
  • streak-kit-map@1.0.0

While these packages provide legitimate functionality, they also contain code that drops a Linux backdoor, masquerading as a native math accelerator. The backdoor, referred to as the RedShell Linux beacon, communicates with remote servers to facilitate post-exploitation activities.

RedC2 4.0 is marketed on cybercrime forums as a versatile toolkit for various operating systems, including Windows, macOS, and Linux, offering capabilities such as surveillance and credential theft. The framework has been under active development, with previous versions released in early 2026 and earlier.

Notably, the RedC2 framework includes an AI-driven component called Red Agent, which allows operators to execute complex tasks using natural language commands. This integration of AI into the command-and-control framework represents a significant evolution in cybercrime tools, lowering the barrier for less experienced operators to conduct sophisticated intrusions.

The findings highlight the ongoing threat posed by malicious npm packages and the increasing sophistication of cybercriminal tools. As these developments unfold, organizations are urged to remain vigilant and implement robust security measures to protect against such threats.

For further details, refer to the report by The Hacker News.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

IDScan Confirms Data Breach Exposing 153 Million Driver’s License Scans for Sale on Dark Web

Identity verification firm IDScan has confirmed a data breach that has exposed scans of approximately 153 million driver’s licenses, with the information reportedly available...

NVIDIA and Palantir Collaborate to Enhance Supply Chain Sovereignty with AI Solutions

Palantir Technologies Inc. and NVIDIA have announced a strategic collaboration aimed at enhancing supply chain sovereignty through advanced artificial intelligence (AI) solutions. This partnership...

Microsoft Warns of AI-Enhanced Executive Impersonation and Invoice Fraud Campaigns

In a concerning trend, threat actors are leveraging artificial intelligence (AI) to enhance their tactics in executing executive impersonation and invoice fraud schemes. Recent...

NASA’s SARSAT technology aids in rescue of five fishermen at sea

NASA's Search and Rescue Satellite-Aided Tracking (SARSAT) technology played a crucial role in the rescue of five fishermen off the Gulf Coast of Mississippi...