logo

RedC2 AI-Powered Linux Malware Delivered Through Malicious npm Packages

ID: 1cdce947-9140-5cfe-97aa-3ac1b521bc14

STIX ID: report--1cdce947-9140-5cfe-97aa-3ac1b521bc14

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Kavichselvan

...
...

TrendAI Research uncovered a supply-chain campaign distributing a native Linux backdoor (RedShell) via trojanized npm packages that silently launch an embedded ELF on import; the implant connects to hardcoded C2 infrastructure (217.60.77.63:8792/8060), supports credential theft, proxying, and in-memory execution, and persists via cron/systemd/auto-start methods. The report includes technical details of the loader (async IIFE bypassing --ignore-scripts), the confirmed SHA-256 (4537B1189CE419F1A595CF47216C03F80E9170CE80DAD8D9227A1E52F9CB3466), recommended detection/hunting steps, and notes an LLM-backed Red Agent command layer enabling natural-language operator commands.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.