14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Researchers found trojanized npm packages that pretend to be calendar and streak utilities while secretly deploying RedC2 4.0’s AI-powered Linux implant, RedShell. The campaign uses a simple import to trigger execution and is linked to a broader, evolving C2 framework promoted by the threat actor MarlboroMan via Red Offsec. #RedC2 #RedShell #MarlboroMan #RedOffsec

Keypoints

  • Multiple npm packages were found to be trojanized and still functioned as advertised.
  • A single import of the package can launch the embedded Linux implant automatically.
  • The hidden payload delivers RedShell, the Linux beacon for RedC2 4.0.
  • RedC2 4.0 includes AI-driven command execution through its Red Agent component.
  • The framework is marketed by Red Offsec and linked to the threat actor MarlboroMan.

Read More: https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html