Mastodon Skip to content
live markets
S&P 5007,674.37▲ 2.20%NASDAQ26,180.46▲ 1.33%DOW53,277.01▲ 2.02%GOLD4,680.60▲ 14.97%WTI87.06▲ 2.53%BRENT94.39▲ 3.71%EUR/USD1.1678▲ 2.28%USD/JPY158.94▼ 2.18%DXY98.84▼ 2.31%BTC$77,287▲ 0.90%ETH$2,424▲ 2.00%SOL$93.98▲ 3.70%TOTAL CRYPTO$2.64T▼ 1.47%
pulseofnations.
UTC --:--NYC --:--LON --:--WAW --:-- bluesky ↗ Join the wire

14 Trojanized npm Packages Deploy AI-Powered Linux Backdoor

Researchers uncover 14 malicious npm packages that secretly install RedC2 4.0, an AI-assisted command-and-control framework designed to maintain stealthy access to Linux servers.

Partner Surfshark VPN

Cybersecurity researchers have discovered a set of 14 trojanized npm packages that secretly deploy RedC2 4.0, an AI-assisted command-and-control framework targeting Linux systems with advanced evasion capabilities.

The campaign, disclosed by The Hacker News on August 21, 2026, found the packages masquerading as calendar utilities and streak-tracking tools. Each package contains a simple import statement that, once executed, silently installs a Linux implant called RedShell. The malicious packages were published from the same owner account and removed within 86 to 107 minutes, suggesting a deliberate fast-in-fast-out strategy to avoid automated detection systems.

A Commercial Malware-as-a-Service Platform

RedC2 is not a one-off tool. Version 3.0 of the framework was sold earlier in January 2026, while version 2.0 was released in August 2025, indicating the framework has been under active development for at least a year. The latest 4.0 release integrates AI-assisted command generation, allowing the operator to issue natural-language instructions to the implant rather than writing manual scripts. The tool is marketed by a threat actor operating under the alias MarlboroMan through a brand called Red Offsec, priced at $99.99.

RedShell uses multiple techniques to hide its presence on compromised systems. It can process attacker commands, exfiltrate data, and establish persistent backdoor access while evading standard endpoint detection tools. The AI-assisted component reportedly helps the operator generate obfuscated payloads on the fly, making signature-based detection more difficult.

Supply Chain Risks Escalate

The npm incident is part of a broader wave of supply chain attacks hitting the JavaScript ecosystem. Earlier in August 2026, Datadog documented a worm that compromised hundreds of popular npm packages, some with over 150 million weekly downloads, using a propagation mechanism to spread across maintainers’ accounts. Red Hat also disclosed a separate incident, advisory RHSB-2026-006, in which attackers compromised a Red Hat employee’s GitHub account to inject malicious workflows into 32 packages under the @redhat-cloud-services namespace.

The npm campaign specifically targeted Linux server environments, where Node.js applications are widely deployed as backend services. Once installed, the trojanized packages establish persistence and allow remote command execution, giving attackers ongoing access to development or production infrastructure. The use of encrypted command channels and AI-generated payloads makes forensic analysis significantly harder.

Security researchers recommend that organizations audit their dependencies for the specific packages identified in the disclosure, verify package provenance through lockfiles and hash verification, and implement runtime monitoring for unexpected network connections. The npm ecosystem’s open publishing model continues to present challenges as threat actors iterate on increasingly sophisticated evasion techniques.

Sources: The Hacker News; Datadog Security Labs; Red Hat Security Advisory RHSB-2026-006

React to this dispatch
Share this dispatch X WhatsApp Report an error

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch Zero-Click Grok Attack Lets Hackers Steal Chat History Read →