logo

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

ID: 787f93b0-6049-539c-b402-b8406dc07f3d

STIX ID: report--787f93b0-6049-539c-b402-b8406dc07f3d

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-08-21

Date Updated: 2026-08-22

Author: [email protected] (The Hacker News)

...
...

Security researchers found functional-looking npm packages that are trojanized to drop and execute a bundled Linux backdoor (RedShell) — part of the RedC2 4.0 C2 framework — when imported; the report lists affected package names and bundled binary filenames, describes delivery/execution TTPs (automatic execution on module import), and summarizes RedC2 capabilities including credential theft, persistence, remote command execution, and an LLM-powered automation layer.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.