Link copied!
Daksh

RedC2 4.0 Linux Backdoor Discovered in 14 Trojanized npm Packages

Aug 30, 2026 1636 words · 23 min read Share

Researchers studying cybersecurity have found a collection of trojanized npm packages that pose as functional calendar and streak tools but are actually designed to covertly install RedC2 4.0, a Linux implant driven by artificial intelligence (AI).

TrendAI, Trend Micro, Enterprise Cybersecurity Business, Report, Thursday

The bundled binary is found, marked executable, and started as a detached background process when the module loads.                       

The payload can be executed with just one import, even a transitive one, anywhere in the dependency hierarchy; no install hook function call is required.

 

The list of identified packages is below -

     streak-metrics-math@1.0.0,1.0.1

     kit-map-vim@1.0.0

     streak-map-cache@1.0.0

     streak-map-kit@1.0.0

     map-streak-kit@1.0.0

     streak-cache-map@1.0.0

     streak-calc-metrics@1.0.0

     streak-calc-math@1.0.0

     streak-math-abz@1.0.0

     streak-metricsaz@1.0.0

     streak-math-metrics@1.0.0

     streak-metricazbd@1.0.0

     streak-metricsazb@1.0.0

     streak-kit-map@1.0.0

 

These packages are noteworthy because they provide the stated functionality and are functioning. Beneath that clothing of date utilities, however, is code that poses as a native math accelerator to drop a Linux backdoor. Each package has a different file name: math-core.bin, math-calc.bin, calc-math.dat, calc-cache.bin, calc.bin, and calc-mapping.bin.

 

The RedShell Linux beacon for RedC2 4.0, which connects to a distant Windows or Linux server to enable post-exploitation actions on the compromised host, is contained in both the "dist" and "dist/internal" directories.

Aliakbar Zahravi, Security Researcher

"The package entry file, dist/index.mjs, serves as a trojan loader and handles delivery."

"Without the need for an install hook or an exposed function, it re-exports the date helpers and initiates the packaged implant as soon as the module loads."

"Red Agent, an LLM-backed command execution layer that converts natural-language intent into framework beacon commands, is an AI assistant included with RedC2."

According to Red Offsec, it is an "AI-powered command execution system specialized for penetration testing."

 

RedC2 4.0 is a cross-platform toolkit for Windows, macOS, and Linux that is advertised on cybercrime forums. It provides mass-operation capabilities, payload loading, credential stealing, and surveillance. Early in June 2026, a threat actor going by the name "MarlboroMan" promoted the version on Hack Forums, calling it a command-and-control (C2 or C&C) framework "built for evasion."

RedC2 has been actively developed for at least a year, as seen by the sale of version 3.0 earlier this January and the August 2025 release of version 2.0. Version 4.0 introduced the RedShell Linux beacon.

 

Terminal access, file transfer, staged payload delivery, data collection, multi-beacon operation, network visualization, host-to-host tunneling, and in-memory execution of Beacon Object Files (BOFs),.NET assemblies, and shellcode are all supported by the feature-rich C2 framework.

 

image shows red-c2-4.0-linux-backdoor

 

Once deployed, the Linux version of the beacon offers an interactive shell via "-bin/sh" and exposes Linux-specific commands to facilitate system discovery, file operations, data collection (such as SSH keys and browser credentials), execution, persistence, in-memory ELF execution, SOCKS5 proxying, and network pivoting.

 

Additionally, it connects to a C2 server and registers the compromised system by collecting basic system data and sending it as a "check-in message." It then goes into a command-processing loop to process the operator's incoming instructions, run them using "-bin/sh," and return the results.

 

File operations, host and network reconnaissance, user enumeration, and data harvesting are all covered by the Windows and macOS counterparts. Additionally, the Windows beacon has features that the macOS version does not have, such as User Account Control (UAC) bypass, antivirus and endpoint detection, antivirus tampering, in-memory execution, and lateral movement.

 

The threat actor states, "Red C2 is a multi-language, multi-OS command and control framework designed for Windows, Linux, and macOS," on a clearnet website called Red Offsec. Using the most recent advancements and methods in the field of offensive security, the complete framework was constructed with evasion as a fundamental principle. You may buy it for $99.99.

 

Customers are specifically forbidden by Red Offsec's Terms of Service from using the program for "unauthorized computer access," "hacking without explicit permission," and "abuse, exploitation, or damage of systems you do not own or are not authorized to test."

Terms

"Red Offsec provides tools intended for red team professionals and users who understand external offensive security tooling within legal and ethical boundaries."

 

RedC2 expands its control layer with a command-line extension called RedC2 EXT and a large language model (LLM)-driven component called Red Agent, which enables operators to use natural language commands to coordinate intricate post-exploitation tasks like network reconnaissance and credential dumping.

 

The results highlight how malicious npm packages are being used to propagate previously unreported AI-integrated C2 frameworks while also reducing entrance barriers.

TrendAI

"By interacting with a model tuned for red-team operations, an operator inputs natural-language prompts, and the framework translates them into actionable command sequences."

 

"This abstraction lets operators of varying skill levels execute complex, multi-stage intrusions efficiently."

 

The development occurs shortly after three legitimate Rust crates (arrayref@0.3.10, internment@0.8.7, and append-only-vec@0.1.9) were compromised by a coordinated supply chain attack that used a malicious proc-macro1 dependency to automatically execute cross-platform malware during Cargo builds.

 

In order to task and download further payloads, the malware is made to profile the compromised device, catalog Chromium-based browsers, create persistence, and beacon to infrastructure under the control of the attacker.

 

It is believed that the poisoned versions were sent to the package repository via compromising the maintainer's publishing credentials. There is evidence of infrastructure overlap with previous software supply chain attacks against Mastra and Axios, both of which are associated with North Korean threat actors.


Conclusion


If you want to protect yourself against such attempts, you can go for a reliable security solution, ThreatFusionAI, a dedicated threat intel platform offered by Craw Security. This amazing platform offers notifications about current cyber threats that gives the time to prepare better security measures to protect yourself. What are you waiting for? Contact, Now!

Topics
Share this article
🧑‍💻
Daksh
Lead Threat Analyst · ThreatFusionAI

Cyber security researcher specializing in mobile malware analysis, OSINT, and digital forensics. Tracks financially motivated threat actors across South & Southeast Asia.

✖ @threatfusionaiin/company/threatfusionaiContact
Previous
How Does Threat Intelligence Improve Incident Response for Enterprise SOCs?

Related Posts

Latest Threat Research

View all