Logo
News Ababil
Explore
SYS_NODE: ONLINE // Cyber Security

RedC2 4.0 Linux Backdoor Unveiled in 14 Trojanized npm Packages

DECRYPTED BY: Nova Stirling | TIMESTAMP: 2026-08-22 T 09:15:00 Z | [ 1 MIN READ ]
RedC2 4.0 Linux Backdoor Unveiled in 14 Trojanized npm Packages
1 Min Read
Share

RedC2 4.0 Linux backdoor hides in npm calendar tools

Cybersecurity analysts at Trend Micro have uncovered a coordinated campaign that injects the RedC2 4.0 Linux backdoor into fourteen npm packages masquerading as calendar or streak‑tracking utilities. When a developer imports the compromised module, the code silently extracts a bundled binary, marks it executable, and spawns it as a detached background process.

“When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process,” the researchers noted.

The payload, a lean ↓ 12 KB AI‑assisted implant, connects to command‑and‑control servers that can issue arbitrary Linux commands, exfiltrate files, and even deploy additional malware. Its AI component adapts beacon intervals to evade typical network‑traffic baselines.

Impact on the JavaScript ecosystem

Package downloads surged before the malicious code was flagged, exposing thousands of projects to potential compromise. Developers are urged to verify package integrity against official repositories and to scan dependencies with tools such as Reuters security alerts or Bloomberg advisories.

Trend Micro recommends immediate removal of the affected packages, regeneration of SSH keys, and a review of system logs for anomalous activity.

Words by: Nova Stirling
Aerospace & Space Tech Correspondent
Global Data Feed

More from this Intel

Cyber Pros Needed to Defend City Hall – Join the Volunteer Shield

Cyber Pros Needed to Defend City Hall – Join the...

Aug 21, 2026
CUSTODY Framework Redefines AI Agent Containment Within Enterprise Networks

CUSTODY Framework Redefines AI Agent Containment Within Enterprise Networks

Aug 21, 2026
What Every Buyer Must Know About TV Streaming Stick Ad Fraud

What Every Buyer Must Know About TV Streaming Stick Ad...

Aug 20, 2026
AI Mind Viruses Threaten Autonomous Agents: New Study Reveals Cross‑Prompt Propagation

AI Mind Viruses Threaten Autonomous Agents: New Study Reveals Cross‑Prompt...

Aug 19, 2026
Ransomware Gangs Exploit Windows Task Host Vulnerability, CISA Warns

Ransomware Gangs Exploit Windows Task Host Vulnerability, CISA Warns

Aug 18, 2026
Canadian Hacker Connor Moucka Pleads Guilty in Snowflake Extortion Scheme

Canadian Hacker Connor Moucka Pleads Guilty in Snowflake Extortion Scheme

Aug 18, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.