Find notable cyber news and cases, enriched with sources, timelines, and signals.

Trojanized npm packages deliver RedC2 4.0 Linux implant

Malware Activity
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

Trojanized npm packages are now delivering the RedC2 4.0 Linux implant through a supply-chain execution path, turning a routine package import into remote malware deployment. The payload runs as soon as the module loads, so a single transitive dependency can trigger compromise without any install hook or user action. The package set also supports credential theft, persistence, discovery, and command-and-control tasking. The activity expands the reach of an AI-assisted C2 framework across Windows, Linux, and macOS.

Related Happenings

MarlboroMan ecosystem shift changes threat-actor operations

Threat Actor Meta
H score32 First: 21.08.2026 21:53 Last: 21.08.2026 21:53 Sources 1

How related: RedC2 4.0, marketed on cybercrime forums as a cross-platform toolkit for Windows, macOS, and Linux, offers surveillance, credential theft, payload loading, and mass-operation capabilities.

About this happening: MarlboroMan publicly marketed RedC2 4.0 as a cross-platform C2 framework, widening access to evasion-focused intrusion tooling across Windows, macOS, and Linux. Th...

TeamPCP Mini Shai-Hulud npm supply-chain campaign

Campaign
H score75 First: 12.05.2026 14:07 Last: 12.05.2026 14:07 Sources 1

About this happening: The TeamPCP-linked Mini Shai-Hulud campaign is an active npm supply-chain operation that steals developer credentials and abuses trusted publishing paths to spread trojani...

Timeline

  1. 21.08.2026 21:53 2 articles · 2h ago

    Trojanized npm packages deliver RedC2 4.0 Linux implant

    Initial Disclosure

    Researchers identified 14 npm packages that masquerade as calendar and streak utilities while delivering the RedC2 4.0 AI-powered Linux implant. The package entry file dist/index.mjs acts as a trojan loader, marking the bundled binary executable and launching it on module load so a single transitive import can trigger a detached RedShell beacon and post-exploitation check-in activity.

    Show sources