14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Researchers studying cybersecurity have found a collection of trojanized npm packages that pose as functional calendar and streak tools but are actually designed to covertly install RedC2 4.0, a Linux implant driven by artificial intelligence (AI).
According to a research released on Thursday by TrendAI, Trend Micro's enterprise cybersecurity division, when the module loads, it finds the bundled code, labels it executable, and starts it as a detached background process. "A single import anywhere in the dependency hierarchy, even a transitive one, is sufficient to execute the payload; no install hook function call is required.
The list of identified packages is below -
streak-metrics-math@1.0.0,1.0.1kit-map-vim@1.0.0streak-map-cache@1.0.0streak-map-kit@1.0.0map-streak-kit@1.0.0str...

