14 npm packages used to deliver RedC2 4.0 on LinuxResearchers identified 14 trojanized npm packages distributing the RedC2 4.0 backdoor on Linux, with command-and-control activity assisted by AI-driven workflows. The campaign abused the npm ecosystem to stage malware through seemingly legitimate packages, extending a software supply chain intrusion path into developer environments and Linux hosts via npm packages.
https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html