RedC2 AI-Powered Linux Malware Delivered Through Malicious npm Packages
Brief
Security researchers have uncovered a supply-chain campaign distributing a native Linux implant tied to RedC2, a commercial multi-OS command-and-control (C2) framework marketed on Hack Forums, through a cluster of trojanized npm packages that represent a growing threat in npm supply chain attacks .
The findings come from TrendAI Research, which analyzed the packages and reverse-engineered the embedded implant, dubbed RedShell Linux.
RedC2 AI-Powered Linux Malware Uses npm Packages
The malicious packages including streak-metrics-math , kit-map-vim , streak-map-cache , map-streak-kit , streak-calc-math , and at least eight other similarly named variants present themselves as dependency-free calendar and “streak” math utilities.
Each contains genuinely functional date-math code in dist/internal/daymath.
