RedC2 AI-Powered Linux Malware Delivered Through Malicious npm Packages
ID: 1cdce947-9140-5cfe-97aa-3ac1b521bc14
STIX ID: report--1cdce947-9140-5cfe-97aa-3ac1b521bc14
Feed Name: Cyber Press
TrendAI Research uncovered a supply-chain campaign distributing a native Linux backdoor (RedShell) via trojanized npm packages that silently launch an embedded ELF on import; the implant connects to hardcoded C2 infrastructure (217.60.77.63:8792/8060), supports credential theft, proxying, and in-memory execution, and persists via cron/systemd/auto-start methods. The report includes technical details of the loader (async IIFE bypassing --ignore-scripts), the confirmed SHA-256 (4537B1189CE419F1A595CF47216C03F80E9170CE80DAD8D9227A1E52F9CB3466), recommended detection/hunting steps, and notes an LLM-backed Red Agent command layer enabling natural-language operator commands.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
