ARTIFICE DAILY AI + CYBER SECURITY BRIEFING

Artificial Intelligence · Cybersecurity

Trojanised npm packages deliver RedC2 4.0 Linux backdoor

TrendAI said 14 npm packages copied calendar and streak utilities while loading a Linux implant tied to RedC2 4.0, a framework marketed with AI-driven command execution tools.

The Hacker News

TrendAI said 14 npm packages were trojanised and presented themselves as calendar and streak utilities. It said the packages still provided the promised functions, but also carried code meant to load a Linux implant.

The loader sat in the package entry file and ran when the module was imported, according to TrendAI and Aliakbar Zahravi. The same binary appeared under different names inside dist/ or dist/internal/, and the article identified it as the RedShell Linux beacon used by RedC2 4.0.

The article said RedC2 4.0 had been sold on Red Offsec’s site for $99.99 and promoted on Hack Forums in early June 2026 by a threat actor called MarlboroMan. It said version 3.0 had been sold in January and version 2.0 in August 2025.

The article said the framework supported terminal access, file transfer, payload delivery, data collection, multi-beacon operation, network mapping, tunnelling and in-memory execution of BOFs, .NET assemblies and shellcode. It also said RedC2 included Red Agent, an LLM-based component for turning natural-language prompts into commands, and ended by linking the npm case with a recent Rust-crate supply-chain incident that investigators thought may have involved stolen publishing credentials.

Named in this story

People

Aliakbar Zahravi
security researcher quoted on the package loader

Organisations

TrendAI
Trend Micro’s enterprise cybersecurity business that reported the findings
Red Offsec
the site that sold RedC2 4.0

Products and systems

RedC2 4.0
the command-and-control framework whose Linux beacon was delivered by the packages
Red Agent
the LLM-driven component for natural-language tasking
streak-metrics-math@1.0.0,1.0.1
one of the trojanised npm packages
kit-map-vim@1.0.0
one of the trojanised npm packages
streak-map-cache@1.0.0
one of the trojanised npm packages
streak-map-kit@1.0.0
one of the trojanised npm packages
map-streak-kit@1.0.0
one of the trojanised npm packages
streak-cache-map@1.0.0
one of the trojanised npm packages
streak-calc-metrics@1.0.0
one of the trojanised npm packages
streak-calc-math@1.0.0
one of the trojanised npm packages
streak-math-abz@1.0.0
one of the trojanised npm packages
streak-metricsaz@1.0.0
one of the trojanised npm packages
streak-math-metrics@1.0.0
one of the trojanised npm packages
streak-metricazbd@1.0.0
one of the trojanised npm packages
streak-metricsazb@1.0.0
one of the trojanised npm packages
streak-kit-map@1.0.0
one of the trojanised npm packages

How the source tells it

The piece mostly used standard security-reporting language, but it still leaned on alarm and AI hype around stealth, evasion and automated command tools.

  • alarm loaded language around trojanised packages, backdoors and post-exploitation activity
  • hype AI branding and capability lists repeated from the framework’s own marketing claims