
Trojanized npm Packages Deploy AI-Powered Linux Backdoor RedC2 4.0
CybersecurityMalwareSupplyChainAttacksAIThreats
Cybersecurity researchers identified 14 trojanized npm packages posing as legitimate calendar and streak utilities, which covertly deploy an AI-powered Linux backdoor named RedC2 4.0. Upon loading, the malicious module extracts a bundled binary, grants it executable permissions, and executes it as a detached background process. The attack targets npm’s package ecosystem, though no specific dates, affected versions, or CVE IDs were disclosed. The RedC2 4.0 implant leverages AI capabilities for command-and-control (C2) operations, though further technical details on its functionality were not provided. The discovery was attributed to Trend Micro’s research team, referenced as TrendAI in the report.