Forensic Summary
Fourteen trojanized npm packages posing as calendar and streak utilities have been discovered delivering RedShell, the Linux beacon component of RedC2 4.0 — a commercially sold, AI-assisted command-and-control framework. The packages are functional by design, lowering suspicion while silently launching a detached backdoor process on import with no install hook required. RedC2 4.0 supports credential theft, in-memory execution, tunneling, and multi-beacon operations, making successful deployment a significant post-exploitation risk for any Linux environment that consumes affected packages.
Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/redc2-4-0-ai-assisted-backdoor-hidden-in-npm-packages/
Top comments (0)