← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 24, 2026 · 11:09via CyberPress

RedC2 AI-Powered Linux Malware Delivered Through Malicious npm Packages

Brief

Security researchers have uncovered a supply-chain campaign distributing a native Linux implant tied to RedC2, a commercial multi-OS command-and-control (C2) framework marketed on Hack Forums, through a cluster of trojanized npm packages that represent a growing threat in npm supply chain attacks .

The findings come from TrendAI Research, which analyzed the packages and reverse-engineered the embedded implant, dubbed RedShell Linux.

RedC2 AI-Powered Linux Malware Uses npm Packages

The malicious packages including streak-metrics-math , kit-map-vim , streak-map-cache , map-streak-kit , streak-calc-math , and at least eight other similarly named variants present themselves as dependency-free calendar and “streak” math utilities.

Each contains genuinely functional date-math code in dist/internal/daymath.

Read more on CyberPress