negativeSYS.SOURCE: The Hacker News• 2026-08-22T00:23:00+05:30
14 Malicious npm Packages Deploy AI-Enhanced RedC2 4.0 Linux Backdoor via Supply Chain Attack
14 trojanized npm packages were discovered delivering RedC2 4.0, an AI-powered Linux backdoor that uses natural language processing for command execution. The malicious payloads exploit package dependencies to deploy a cross-platform C2 framework with advanced post-exploitation capabilities.
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0.
"When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process," TrendAI, Trend Micro's
*** END OF TRANSMISSION ***