Threat reportSupply ChainTL-2026-2099

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

criticalACTIVE

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor (TL-2026-2099), also tracked as RedC2, is a critical-severity supply-chain compromise, first published 2026-08-21. It is attributed to MarlboroMan with medium confidence, affects npm (OpenJS Foundation) npm Registry, maps to 23 MITRE ATT&CK techniques (T1020, T1036.005, T1037.003), and is covered by 9 detection rules and 32 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
23MITRE ATT&CK
Actors
1MarlboroMan
Detection rules
9SPL · KQL · Sigma
IOCs
32Indicators of compromise

Key facts for TL-2026-2099

Threat ID
TL-2026-2099
Also known as
RedC2, RedShell, Red Agent, RedShellixo
Severity
CRITICAL
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
MarlboroMan
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
technology, software-development
Target regions
Global
Detection rules
9
Indicators of compromise
32

Malware and tooling in 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor

Malware and tooling: Cobalt Strike, RedC2, RedShell, RedShellixo, Trojan, RedC2

How 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor works

TrendAI (Trend Micro) discovered 14 trojanized npm packages masquerading as calendar/streak calculation utilities that deliver the RedC2 4.0 RedShell Linux backdoor. The packages execute on module import via an async IIFE in dist/index.mjs, bypassing npm's --ignore-scripts safeguard, dropping a Linux ELF binary disguised as a native math accelerator. RedC2 4.0 is marketed by threat actor MarlboroMan on Hack Forums at $99.99 and includes the RedShell implant (remote shell, credential theft, SOCKS5 pivoting, fileless execution via memfd_create, four persistence mechanisms) plus Red Agent — an LLM-backed natural-language-to-command translation engine that dramatically lowers the barrier to entry for offensive operations.

On August 20, 2026, TrendAI Research (Aliakbar Zahravi) published an analysis of 14 trojanized npm packages that deliver the RedC2 4.0 RedShell Linux backdoor — a commercial cross-platform C2 framework marketed on Hack Forums by the threat actor MarlboroMan since June 2026. The packages (all version 1.0.0 except streak-metrics-math which also has 1.0.1) were published to the npm registry between late July and mid-August 2026 under names designed to appear as legitimate calendar streak/date-math utilities: streak-metrics-math, kit-map-vim, streak-map-cache, streak-map-kit, map-streak-kit, streak-cache-map, streak-calc-metrics, streak-calc-math, streak-math-abz, streak-metricsaz, streak-math-metrics, streak-metricazbd, streak-metricsazb, and streak-kit-map. Amazon Inspector and the Open Source Vulnerability (OSV) database issued multiple malware advisories (MAL-2026-12114, MAL-2026-12311, MAL-2026-13403, MAL-2026-13519, MAL-2026-13915 and others).

Each package bundles legitimate date-math implementation alongside a malicious Linux x86_64 ELF binary in dist/ or dist/internal/ directories, named to suggest native math acceleration (math-core.bin, calc-cache.bin, math-calc.bin, calc-math.dat, calc.bin, calc-mapping.bin). All variants share the same SHA-256 hash (4537b1189ce419f1a595cf47216c03f80e9170ce80dad8d9227a1e52f9cb3466), confirming a shared build pipeline. The entry file dist/index.mjs re-exports date helpers from dist/internal/daymath.mjs but contains an async IIFE executing at module load time — not via npm lifecycle hooks. This design specifically bypasses npm's --ignore-scripts safeguard (which only blocks install/uninstall hooks). A single import anywhere in the dependency graph, including transitive imports, triggers payload execution. The loader chmods the bundled binary to 0755, performs a SHA-256 integrity check (execution continues even on mismatch with only a log-level change), and spawns the implant as a detached child process via child_process.spawn with detached:true and shell:false, placing it in its own process group to survive the parent Node process.

The delivered binary is RedShell, the native Linux implant of RedC2 4.0 — a C2 framework in active development since at least August 2025 when v2.0 was first documented. RedC2 is marketed by MarlboroMan on Hack Forums at $99.99 with a clearnet website (Red Offsec) as its commercial presence. Version history: v2.0 added RedC2 EXT CLI and Red Agent; v3.0 (January 2026) added multi-operator terminals and macOS beacons; v4.0 (June 1, 2026) introduced the RedShell native Linux implant with in-framework beacon compilation; v4.1 (July 19, 2026) added cross-network shell tunneling; v4.1.3 (August 5, 2026) extended with WSL support and Linux CLI client.

RedShell is a full-featured Linux RAT. Upon execution, it ignores SIGPIPE, double-forks to daemonize, records its working directory, and enters an infinite reconnection loop. It establishes a TLS 1.2+ connection to hardcoded C2 IP 217.60.77.63:8792 (hosted by Miteflux Technologies / ServerExpress, AS203861, 124 City Road, London), with 127.0.0.1:8792 as fallback. TCP uses TCP_NODELAY with aggressive keepalive (1s initial, 3s interval, 5 failures drop). Certificate verification is disabled (SSL_VERIFY_NONE). All command traffic uses a custom three-round XOR + ROR1 (rotate right by 1 bit) cipher over TLS. The implant sends a SECURE_BEACON check-in containing username, hostname, OS/kernel/architecture, root status, public IP (queried via api.ipify.org), and a persistent installation ID (stored at ~/.config/.rsvc, generated from OpenSSL RAND_bytes or timestamp+PID fallback). Commands use length-prefixed binary frames dispatched against 45+ handlers covering system recon, file operations, credential theft, process/account management, and network pivoting.

RedShell supports four persistence mechanisms: systemd user service (~/.config/systemd/user/svc-update.service with Description='System Update Service' and Restart=always), cron (@reboot), ~/.bashrc modification, and XDG autostart entries. A single /persist remove command removes all four. Fileless execution uses memfd_create (syscall 319) for in-memory ELF execution and mmap with executable permissions for shellcode, both via a three-stage staging protocol (membegin/memchunk/memrun). The implant provides SOCKS5 proxy, TCP port forwarding, and cross-network shell tunneling (RC2TUN protocol, Base64 over main C2 channel).

RedC2 ships with Red Agent, an LLM-backed command execution layer accessed via /ra in any beacon terminal. Red Agent translates natural-language intents (e.g., 'dump credentials' or 'locate SSH keys') into ordered chains of beacon commands via keypoint analysis, with full session state visibility and execution authority. This dramatically reduces the skill barrier for effective offensive operations.

Multi-channel exfiltration: bulk data to 217.60.77.63:8060 via chunked HTTP POST (base64-encoded, BIGEXTRACT START/END framing), file downloads from 217.60.77.63:8888, and external uploads to litterbox.catbox.moe via standard HTTPS (with CA validation). Targeted data includes SSH keys (~/.ssh/), browser credential stores, database files, environment variables, and arbitrary filesystem paths. The implant also probes 8.8.8.8:53/UDP to determine its local routing address.

No CVEs have been assigned. Adjacent IP 217.60.77.23 in the same /24 has been flagged for SSH brute-force activity. Trend Micro released IPS signature 47909 (HTTP: Backdoor.Linux.RedShellixo.A Runtime Detection) and published Vision One detection queries. Remediation requires immediate isolation, full credential rotation from a clean machine, blocking 217.60.77.0/24 at perimeter, and auditing npm dependency trees for the 14 packages. Package removal alone is insufficient due to persistence mechanisms.

MITRE ATT&CK techniques used in TL-2026-2099

Exfiltration

T1020 Automated Exfiltration

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1564.001 Hide Artifacts: Hidden Files and Directories

Persistence

T1037.003 Network Logon Script; T1053.003 Scheduled Task/Job: Cron; T1543.002 Create or Modify System Process: Systemd Service; T1547.015 Login Items

Discovery

T1057 Process Discovery; T1082 System Information Discovery

Execution

T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.007 JavaScript; T1106 Native API; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1219 Remote Access Tools; T1573.001 Encrypted Channel: Symmetric Cryptography

command-and-control

T1090.001 Internal Proxy

Initial Access

T1195.001 Compromise Software Dependencies and Development Tools

defense-impairment

T1222.002 Linux and Mac Permissions

Credential Access

T1552.004 Private Keys; T1555 Credentials from Password Stores

Affected products and versions in 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor

  • npm (OpenJS Foundation) — npm Registry
    Vulnerable versions: 14 packages in streak-* and kit-* namespaces at v1.0.0
    Fixed in: Packages removed from registry following TrendAI and Amazon Inspector detection
  • Node.js — npm Ecosystem - All Projects
    Vulnerable versions: Any Node.js deployment importing affected packages (direct or transitive)
    Fixed in: None - requires manual audit and package removal
  • Linux — x86_64 Systems
    Vulnerable versions: All Linux distributions (target platform for RedShell ELF payload)
    Fixed in: N/A - OS-agnostic malware delivery via cross-platform npm ecosystem

Remediation for 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor

Immediate actions

  • Isolate affected systems from the network
  • Block 217.60.77.0/24 CIDR at network perimeter (ports 8792, 8060, 8888 TCP)
  • Uninstall all 14 identified malicious npm packages from every project
  • Remove ~/.config/systemd/user/svc-update.service if present and run systemctl --user daemon-reload
  • Remove ~/.config/.rsvc if present
  • Check crontab for @reboot entries pointing to non-standard paths
  • Check ~/.bashrc for suspicious launch commands
  • Check ~/.config/autostart/ for suspicious .desktop entries
  • Rotate ALL secrets, SSH keys, API tokens, and credentials from a clean, uncompromised machine
  • Run Trend Micro IPS signature 47909 to detect RedShellixo payloads

Workarounds

  • npm --ignore-scripts does NOT protect against this attack class — the IIFE executes at module import time regardless of hook filtering
  • Consider using isolated build environments (containers) with restricted network access for npm install
  • Use npm lockfiles with package integrity verification before deployment
  • Deploy endpoint detection rules for /bin/sh processes spawned by Node.js (node -- eval or child_process)

Longer-term hardening

  • Audit all npm dependency trees for the 14 named packages
  • Implement software composition analysis (SCA) with automated malware scanning across all builds
  • Deploy runtime detection for unexpected child_process.spawn with detached:true from Node.js modules
  • Monitor outbound connections to Miteflux AS203861 IP ranges
  • Implement npm package provenance verification (npm attestation) for production dependencies
  • Use containerized build environments with restricted egress for npm install operations
  • Deploy file integrity monitoring on ~/.config/systemd/user/ for unexpected unit files

Weaknesses (CWE) in 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor

CWE-506, CWE-829

Timeline of 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor

  • RedC2 v2.0 first documented — earliest known version of the RedC2 C2 framework, introducing RedC2 EXT CLI client, Red Agent, MongoDB support, SOCKS proxy, and port forwarding.
  • RedC2 v3.0 released with multi-operator terminal support, macOS beacons, remote desktop capabilities, and credential extraction modules.
  • RedC2 v4.0 released introducing the RedShell native Linux implant with in-framework Linux beacon compilation. Framework advertised on Hack Forums by threat actor MarlboroMan at $99.99.
  • RedC2 v4.1 released adding cross-network shell tunneling via Network Map feature.
  • streak-metrics-math (first trojanized npm package) published to npm registry (v1.0.0). Detected and tracked as GHSA-57m5-24x9-2xr5.
  • RedC2 v4.1.3 released with WSL support and Linux CLI client. streak-calc-math published to npm. Detected as MAL-2026-12114.
  • Amazon Inspector detects streak-cache-map as malicious (IN-MAL-2026-016095). Additional packages published to npm registry on or around this date.
  • streak-kit-map and streak-map-cache published to npm registry. Tracked as MAL-2026-13519 and GHSA-v2fj-c673-2gjm.
  • kit-map-vim published to npm registry. Detected and tracked as MAL-2026-13915 / GHSA-hg96-r46x-6f4w. OSV records show the same RedShell ELF binary hash across all packages.
  • TrendAI Research (Aliakbar Zahravi) publishes full reverse engineering report 'Prompting the Payload' detailing the supply chain attack, RedShell technical analysis, C2 protocol reverse engineering, and detection guidance.
  • Public disclosure via The Hacker News article. npm registry removes the 14 packages. Trend Micro releases IPS signature 47909 (Backdoor.Linux.RedShellixo.A) for detection.

Sources cited for 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor

Detection coverage for TL-2026-2099

As of 2026-08-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2099 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
32 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-2099

6 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats