14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Cybersecurity researchers found 14 trojanized npm packages that deliver an AI-powered Linux backdoor called RedC2 4.0.
Intelligence analysis by Qwen 2.5 (3B)

Researchers discovered 14 npm packages that contain a malicious Linux backdoor called RedC2 4.0, which uses AI to communicate with a C2 server.
Bad people made some packages that look like normal ones, but they actually hide a sneaky computer program that can spy on people's computers and steal their passwords.
Analysis
{"heading_1":"The RedC2 4.0 Backdoor","subheading_1":"RedC2 4.0 is a multi-platform C2 framework that can be used for various malicious activities.","paragraph_1":"RedC2 4.0 uses an AI-assisted C2 framework to evade detection and facilitate post-exploitation activities.","paragraph_2":"The AI-assisted C2 framework supports terminal access, file transfer, staged payload delivery, data collection, multi-beacon operation, network visualization, host-to-host tunneling, and in-memory execution of Beacon Object Files (BOFs), .NET assemblies, and shellcode.","paragraph_3":"The AI-assisted C2 framework can be controlled using natural language commands, making it easier for operators to execute complex, multi-stage intrusions efficiently.","subheading_2":"The npm Package Backdoor","subheading_3":"The AI-Assisted C2 Framework"}
Key points
- 14 npm packages were found to contain a malicious Linux backdoor called RedC2 4.0.
- The backdoor uses an AI-assisted C2 framework to evade detection and facilitate post-exploitation activities.
- The malicious packages masquerade as calendar and streak utilities.
- The malicious code is located within the 'dist/' or 'dist/internal/' directories.
- The AI-assisted C2 framework supports terminal access, file transfer, staged payload delivery, data collection, multi-beacon operation, network visualization, host-to-host tunneling, and in-memory execution of Beacon Object Files (BOFs), .NET assemblies, and shellcode.
Better npm package security measures can prevent these kinds of attacks.
The AI-assisted C2 framework makes it harder to detect and stop these kinds of attacks.



