Researchers found trojanized npm packages that pretend to be calendar and streak utilities while secretly deploying RedC2 4.0’s AI-powered Linux implant, RedShell. The campaign uses a simple import to trigger execution and is linked to a broader, evolving C2 framework promoted by the threat actor MarlboroMan via Red Offsec. #RedC2 #RedShell #MarlboroMan #RedOffsec
Keypoints
- Multiple npm packages were found to be trojanized and still functioned as advertised.
- A single import of the package can launch the embedded Linux implant automatically.
- The hidden payload delivers RedShell, the Linux beacon for RedC2 4.0.
- RedC2 4.0 includes AI-driven command execution through its Red Agent component.
- The framework is marketed by Red Offsec and linked to the threat actor MarlboroMan.
Read More: https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html