logo

Malicious npm Packages Deploy AI-Powered RedC2 Linux Implant to Steal Credentials and Pivot Networks

ID: 0237e9a1-b06a-5638-b186-35566ad13e3f

STIX ID: report--0237e9a1-b06a-5638-b186-35566ad13e3f

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Tushar Subhra Dutta

...
...

Malicious npm packages posing as date/math utilities were used to deploy RedShell, a native Linux backdoor tied to the RedC2 framework: the module entry (dist/index.mjs) makes a bundled binary executable and launches it detached, bypassing npm lifecycle controls. RedShell can steal SSH keys and browser/database credentials, establish persistence (cron, startup files, user services), perform tunneling and proxying (SOCKS5, TCP forwarding), and supports an AI-driven "Red Agent" for natural-language command sequencing. The report provides IoCs (package names, SHA-256 hash, C2 IPs/ports, domains, payload paths), hunting and remediation guidance (isolate hosts, rotate credentials, search telemetry), and recommends tightening dependency approvals and build permissions to reduce supply-chain risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.