Trojanized npm packages deliver RedC2 4.0 Linux implant
Malware Activity
Summary
Hide ▲
Show ▼
Trojanized npm packages are now delivering the RedC2 4.0 Linux implant through a supply-chain execution path, turning a routine package import into remote malware deployment. The payload runs as soon as the module loads, so a single transitive dependency can trigger compromise without any install hook or user action. The package set also supports credential theft, persistence, discovery, and command-and-control tasking. The activity expands the reach of an AI-assisted C2 framework across Windows, Linux, and macOS.
Related Happenings
MarlboroMan ecosystem shift changes threat-actor operations
Threat Actor Meta
H score32
First: 21.08.2026 21:53
Last: 21.08.2026 21:53
Sources 1
How related:
RedC2 4.0, marketed on cybercrime forums as a cross-platform toolkit for Windows, macOS, and Linux, offers surveillance, credential theft, payload loading, and mass-operation capabilities.
About this happening:
MarlboroMan publicly marketed RedC2 4.0 as a cross-platform C2 framework, widening access to evasion-focused intrusion tooling across Windows, macOS, and Linux. Th...
MarlboroMan ecosystem shift changes threat-actor operations
Threat Actor MetaHow related: RedC2 4.0, marketed on cybercrime forums as a cross-platform toolkit for Windows, macOS, and Linux, offers surveillance, credential theft, payload loading, and mass-operation capabilities.
About this happening: MarlboroMan publicly marketed RedC2 4.0 as a cross-platform C2 framework, widening access to evasion-focused intrusion tooling across Windows, macOS, and Linux. Th...
TeamPCP Mini Shai-Hulud npm supply-chain campaign
Campaign
H score75
First: 12.05.2026 14:07
Last: 12.05.2026 14:07
Sources 1
About this happening:
The TeamPCP-linked Mini Shai-Hulud campaign is an active npm supply-chain operation that steals developer credentials and abuses trusted publishing paths to spread trojani...
TeamPCP Mini Shai-Hulud npm supply-chain campaign
CampaignAbout this happening: The TeamPCP-linked Mini Shai-Hulud campaign is an active npm supply-chain operation that steals developer credentials and abuses trusted publishing paths to spread trojani...
Timeline
-
21.08.2026 21:53 2 articles · 2h ago
Trojanized npm packages deliver RedC2 4.0 Linux implant
Initial DisclosureResearchers identified 14 npm packages that masquerade as calendar and streak utilities while delivering the RedC2 4.0 AI-powered Linux implant. The package entry file dist/index.mjs acts as a trojan loader, marking the bundled binary executable and launching it on module load so a single transitive import can trigger a detached RedShell beacon and post-exploitation check-in activity.
Show sources
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 — thehackernews.com — 21.08.2026 21:53
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 — thehackernews.com — 21.08.2026 21:53