14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor

A sophisticated supply chain attack delivers the AI-powered RedC2 4.0 framework through 14 trojanized npm packages.

By Central
Malicious npm packages disguised as utilities install the RedC2 4.0 backdoor on Linux systems.
Highlights
  • The 14 malicious npm packages execute their payload upon import, requiring no install hook.
  • RedC2 4.0 is a cross-platform C2 framework sold on cybercrime forums for $99.99.
  • The attack represents a turning point where supply chain threats combine with AI-augmented command-and-control frameworks.

Cybersecurity researchers have uncovered a sophisticated supply chain attack targeting the npm ecosystem: 14 trojanized packages that pose as legitimate calendar and streak utilities but covertly install an artificial intelligence-powered Linux backdoor designated RedC2 4.0. The discovery, detailed by Trend Micro’s TrendAI team, reveals a new level of stealth in open-source malware distribution, where functional code hides a weaponized implant capable of deep system compromise.

The 14 Malicious npm Packages and Their Deceptive Design

The packages, all uploaded to the npm registry, share version numbers 1.0.0 or 1.0.1 and appear to fulfill their advertised purpose—date and streak tracking. Beneath that facade, each package includes a native binary masked as a math accelerator. The binary is stored in the dist/ or dist/internal/ directory under names such as math-core.bin, math-calc.bin, calc-math.dat, calc-cache.bin, calc.bin, or calc-mapping.bin. When the module loads, the entry file dist/index.mjs locates the bundled binary, marks it executable, and launches it as a detached background process. No install hook is required; a single import anywhere in the dependency graph—even a transitive one—triggers the payload.

The full list of identified packages:

Security researcher Aliakbar Zahravi explained that the packages re-export the date helpers while simultaneously launching the bundled implant. This technique avoids typical detection hooks because no install script or exported function explicitly initiates the malicious behavior—the mere act of importing the module is enough.

RedC2 4.0: A Cross-Platform Command-and-Control Framework Built for Evasion

The dropped binary is the RedShell Linux beacon for RedC2 4.0, a command-and-control (C2) framework marketed on cybercrime forums by a threat actor known as “MarlboroMan.” First advertised on Hack Forums in early June 2026, the framework sells for $99.99 through a clearnet website branded Red Offsec. The 4.0 version introduced the Linux beacon, building on version 3.0 released in January 2026 and version 2.0 in August 2025aaa—indicating active development over at least a year.

RedC2 4.0 is cross-platform, supporting Windows, macOS, and Linux. It offers terminal access, file transfer, staged payload delivery, data collection, multi-beacon operation, network visualization, host-to-host tunneling, and in-memory execution of Beacon Object Files (BOFs), .NET assemblies, and shellcode. The Linux beacon, once deployed, provides an interactive shell through /bin/sh and exposes Linux-specific commands for system discovery, file operations, data collection (including SSH keys and browser credentials), persistence, in-memory ELF execution, SOCKS5 proxying, and network pivoting.

The beacon establishes communication with a remote C2 server—which can run on Windows or Linux—by gathering basic system information and transmitting a “check-in message.” It then enters a command-processing loop, executing incoming instructions via /bin/sh and sending the results back. Windows and macOS variants offer similar capabilities, with the Windows version additionally incorporating User Account Control (UAC) bypass, antivirus and endpoint detection evasion, antivirus tampering, and lateral movement.

How Does the RedShell Beacon Operate Once Deployed?

After the trojanized npm module executes the binary, the beacon profiles the infected system, collects identifying data, and sends a check-in to the operator. It then listens for commands, which can range from simple shell commands to complex post-exploitation tasks. The beacon uses /bin/sh for execution, ensuring compatibility across Linux distributions. It can also perform in-memory execution of ELF files, avoiding disk writes that might trigger file-based detection. Additionally, the beacon supports SOCKS5 proxying, allowing the attacker to route traffic through the compromised host and pivot to internal networks.

The AI Integration: Red Agent and Natural Language Command Execution

A distinguishing feature of RedC2 4.0 is its integration of artificial intelligence. The framework ships with an AI assistant called Red Agent, an LLM-backed command execution layer that translates natural-language prompts into framework beacon commands. Red Offsec describes it as “an AI-powered command execution system specialized for penetration testing.” Operators can input natural-language instructions—such as “enumerate all active directory users and extract their SIDs”—and the framework translates these into the necessary sequence of beacon commands.

This abstraction lowers the barrier to entry for attackers, enabling individuals with limited technical expertise to execute complex multi-stage intrusions. TrendAI noted that by interacting with a model tuned for red-team operations, an operator can efficiently orchestrate tasks like network reconnaissance and credential dumping without deep knowledge of underlying tools. The component is part of a broader control layer that also includes a command-line extension called RedC2 EXT.

Red Offsec’s terms of service explicitly prohibit unauthorized computer access and hacking without permission, stating that the tools are intended for red team professionals within legal and ethical boundaries. However, the availability of such a framework on public forums, combined with its distribution through malicious npm packages, suggests that these terms are easily circumvented.

Supply Chain Attack Patterns and Broader Implications

The discovery of these 14 trojanized npm packages comes shortly after a coordinated supply chain attack on three legitimate Rust crates—[email protected], [email protected], and [email protected]—which were compromised with a malicious proc-macro1 dependency that executed cross-platform malware during Cargo builds. That malware profiled infected devices, cataloged Chromium-based browsers, established persistence, and beaconed to attacker-controlled infrastructure for tasking and additional payloads. Evidence suggested the maintainer’s publishing credentials were compromised, and infrastructure overlaps linked the attack to prior campaigns targeting Mastra and Axios, both attributed to North Korean threat actors.

The npm packages follow a similar pattern: functional code masking a hidden payload, automated execution without user interaction, and delivery of a sophisticated C2 framework. This highlights a growing trend where attackers use open-source package repositories as vectors for implanting backdoors into development and production environments. Because these packages appear to work correctly, they evade casual inspection and can persist in dependency trees for extended periods.

What Is RedC2 4.0 and Why Is It Significant?

RedC2 4.0 is a multi-language, multi-OS command-and-control framework that leverages AI in the form of Red Agent to simplify post-exploitation. Its cross-platform nature and evasion-focused design make it a potent tool for both legitimate red teams and malicious actors. The fact that it is being distributed via functional npm packages—rather than through exploit kits or phishing—demonstrates a maturation of supply chain attack strategies. The framework’s price point of $99.99 makes it accessible, and its continuous development (versions 2.0, 3.0, and now 4.0 within a year) indicates sustained investment by its creators.

The significance extends beyond the technical details. The integration of LLMs directly into C2 frameworks reduces the skill barrier for cybercrime, potentially increasing the volume of attacks from less sophisticated actors. Moreover, the use of legitimate-looking open-source packages as delivery mechanisms poses a challenge for security teams that rely on automated scanning and manual code review. Organizations that incorporate npm dependencies into their build pipelines must now consider the risk of transitive dependencies that import seemingly harmless utilities.

Practical Defenses and Industry Context

TrendAI’s report emphasizes the need for robust supply chain security practices. Developers should verify the integrity of packages against known hashes, audit dependencies for unusual binary files, and consider runtime monitoring for processes that spawn child shells or establish unexpected network connections. The presence of native binaries in JavaScript packages—especially those that claim to be pure JavaScript utilities—is a strong red flag. Additionally, package maintainers should enable two-factor authentication on their accounts to prevent credential theft, as seen in the Rust crate incident.

The broader industry context reveals a sustained campaign against open-source ecosystems. The Rust supply chain attack, the Mastra and Axios compromises, and now these npm packages suggest that threat actors are systematically targeting package registries to distribute backdoors. The use of AI in RedC2 4.0 may also foreshadow a future where malware autonomously adapts to its environment, evading sandboxes and signature-based detection. Security researchers and platform operators must collaborate to improve detection of such packages before they reach production systems.

Even as Red Offsec markets its framework under a veneer of ethical red-teaming, the availability of the same tools to malicious actors underscores the dual-use nature of advanced offensive security software. The discoverability of these packages and the subsequent takedown by npm administrators are critical, but the cat-and-mouse game continues. Future iterations may employ even more sophisticated obfuscation, such as encrypted payloads or delayed execution, making detection harder.

The convergence of supply chain attacks with AI-augmented C2 frameworks marks a turning point in the cybersecurity landscape. Organizations that once focused on perimeter defenses must now scrutinize the software supply chain with the same rigor as network traffic. The 14 trojanized npm packages are not an isolated incident—they are a signal of a new operational standard for adversaries who prefer stealth and automation over brute force. Vigilance, automated dependency analysis, and a zero-trust approach to open-source components are no longer optional; they are essential for survival in an increasingly interconnected software ecosystem.

Share This Article