Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Trojanized npm Packages Unveil AI-Driven Linux Backdoor

Trojanized npm Packages Unveil AI-Driven Linux Backdoor

Posted on August 21, 2026 By CWS

Cybersecurity experts have uncovered a series of compromised npm packages masquerading as functional tools but instead deploying an AI-powered Linux backdoor. These packages, posing as calendar and utility applications, secretly install a Linux implant, RedC2 4.0, designed to operate silently in the background without user detection.

Stealthy Deployment through npm Packages

According to a report by TrendAI, a division of Trend Micro, the compromised modules activate the backdoor through a straightforward import process. Once integrated, the modules identify and execute the bundled binary as an independent process, bypassing the need for an installation hook. A single inclusion in any dependency graph triggers the payload execution.

Notably, the packages maintain their advertised functionality while executing malicious tasks. They disguise their true purpose by embedding the backdoor in files named differently across packages, such as math-core.bin and calc-math.dat. These files, hidden within directories, house the RedShell Linux beacon that facilitates communication with remote servers, enabling further exploitation of the compromised systems.

Features of RedC2 4.0

RedC2 4.0, marketed as a versatile cross-platform tool, offers extensive capabilities, including surveillance, credential theft, and payload delivery. Initially promoted by a threat actor known as “MarlboroMan” in June 2026, this tool has been actively developed, with previous versions dating back to August 2025.

The framework boasts numerous features, such as terminal access, file transfers, and network visualization. It supports complex operations like host-to-host tunneling and in-memory execution of various object files. The Linux beacon specifically allows for interactive shell access, system discovery, and data collection, including sensitive information like SSH keys.

AI Integration Enhancing Cyber Threats

RedC2 extends its capabilities with an AI-driven component, Red Agent, which utilizes a large language model to convert natural language inputs into actionable commands. This integration simplifies complex post-exploitation tasks, making them accessible even to operators with limited technical expertise. The AI assistant, as described by security researcher Aliakbar Zahravi, streamlines operations such as network reconnaissance using natural language.

These developments highlight the growing trend of integrating AI into cyber tools, lowering barriers for cybercriminals while expanding their operational reach. The use of AI in these frameworks underscores the need for heightened vigilance and advanced security measures to counteract evolving threats.

Implications and Future Outlook

The discovery of these trojanized packages emphasizes the persistent threat posed by software supply chain attacks. Recent incidents, including attacks on legitimate Rust crates, further illustrate vulnerabilities exploited by threat actors. The compromised npm packages serve as a stark reminder of the importance of monitoring and securing software dependencies.

As attackers continue to refine their techniques, incorporating AI and advanced evasion strategies, cybersecurity efforts must adapt to mitigate potential risks. Organizations are urged to review their software supply chains and enhance their security protocols to safeguard against these sophisticated threats.

The Hacker News Tags:AI integration, AI security, command-and-control, Cybersecurity, Linux backdoor, Linux security, Malware, npm packages, Red Offsec, RedC2 4.0, RedShell, security tools, supply chain attack, TrendAI, Trojan

Post navigation

Previous Post: Microsoft Doubles Mailbox Storage for 365 Users
Next Post: Claude Opus 5 Opts for Easiest Paths in Binary Analysis

Related Posts

Trend Micro Confirms Active Exploitation of Critical Apex One Flaws in On-Premise Systems Trend Micro Confirms Active Exploitation of Critical Apex One Flaws in On-Premise Systems The Hacker News
Critical ASP.NET Core Vulnerability Patched by Microsoft Critical ASP.NET Core Vulnerability Patched by Microsoft The Hacker News
BKA Unveils Key Figures in REvil Ransomware Operations BKA Unveils Key Figures in REvil Ransomware Operations The Hacker News
CTM360 Exposes a Global WhatsApp Hijacking Campaign: HackOnChat CTM360 Exposes a Global WhatsApp Hijacking Campaign: HackOnChat The Hacker News
The Crucial Role of Initial Decisions in Incident Response The Crucial Role of Initial Decisions in Incident Response The Hacker News
Europol and Eurojust Dismantle €600 Million Crypto Fraud Network in Global Sweep Europol and Eurojust Dismantle €600 Million Crypto Fraud Network in Global Sweep The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Apple Enhances macOS Disk Access Amid AI Concerns
  • GlassWorm Exploits VS Code Themes in Supply Chain Attack
  • RemoveMacAI Clears 12GB by Eliminating Apple AI Models
  • ClickFix Campaign Exploits Fake CAPTCHA for Malware
  • AI Exploit in Zammad Exposes Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Apple Enhances macOS Disk Access Amid AI Concerns
  • GlassWorm Exploits VS Code Themes in Supply Chain Attack
  • RemoveMacAI Clears 12GB by Eliminating Apple AI Models
  • ClickFix Campaign Exploits Fake CAPTCHA for Malware
  • AI Exploit in Zammad Exposes Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark