Threat reportSupply ChainTL-2026-2099
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor (TL-2026-2099), also tracked as RedC2, is a critical-severity supply-chain compromise, first published 2026-08-21. It is attributed to MarlboroMan with medium confidence, affects npm (OpenJS Foundation) npm Registry, maps to 23 MITRE ATT&CK techniques (T1020, T1036.005, T1037.003), and is covered by 9 detection rules and 32 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 23MITRE ATT&CK
- Actors
- 1MarlboroMan
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 32Indicators of compromise
Key facts for TL-2026-2099
- Threat ID
- TL-2026-2099
- Also known as
- RedC2, RedShell, Red Agent, RedShellixo
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- MarlboroMan
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 32
Malware and tooling in 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor
Malware and tooling: Cobalt Strike, RedC2, RedShell, RedShellixo, Trojan, RedC2
How 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor works
TrendAI (Trend Micro) discovered 14 trojanized npm packages masquerading as calendar/streak calculation utilities that deliver the RedC2 4.0 RedShell Linux backdoor. The packages execute on module import via an async IIFE in dist/index.mjs, bypassing npm's --ignore-scripts safeguard, dropping a Linux ELF binary disguised as a native math accelerator. RedC2 4.0 is marketed by threat actor MarlboroMan on Hack Forums at $99.99 and includes the RedShell implant (remote shell, credential theft, SOCKS5 pivoting, fileless execution via memfd_create, four persistence mechanisms) plus Red Agent — an LLM-backed natural-language-to-command translation engine that dramatically lowers the barrier to entry for offensive operations.
On August 20, 2026, TrendAI Research (Aliakbar Zahravi) published an analysis of 14 trojanized npm packages that deliver the RedC2 4.0 RedShell Linux backdoor — a commercial cross-platform C2 framework marketed on Hack Forums by the threat actor MarlboroMan since June 2026. The packages (all version 1.0.0 except streak-metrics-math which also has 1.0.1) were published to the npm registry between late July and mid-August 2026 under names designed to appear as legitimate calendar streak/date-math utilities: streak-metrics-math, kit-map-vim, streak-map-cache, streak-map-kit, map-streak-kit, streak-cache-map, streak-calc-metrics, streak-calc-math, streak-math-abz, streak-metricsaz, streak-math-metrics, streak-metricazbd, streak-metricsazb, and streak-kit-map. Amazon Inspector and the Open Source Vulnerability (OSV) database issued multiple malware advisories (MAL-2026-12114, MAL-2026-12311, MAL-2026-13403, MAL-2026-13519, MAL-2026-13915 and others).
Each package bundles legitimate date-math implementation alongside a malicious Linux x86_64 ELF binary in dist/ or dist/internal/ directories, named to suggest native math acceleration (math-core.bin, calc-cache.bin, math-calc.bin, calc-math.dat, calc.bin, calc-mapping.bin). All variants share the same SHA-256 hash (4537b1189ce419f1a595cf47216c03f80e9170ce80dad8d9227a1e52f9cb3466), confirming a shared build pipeline. The entry file dist/index.mjs re-exports date helpers from dist/internal/daymath.mjs but contains an async IIFE executing at module load time — not via npm lifecycle hooks. This design specifically bypasses npm's --ignore-scripts safeguard (which only blocks install/uninstall hooks). A single import anywhere in the dependency graph, including transitive imports, triggers payload execution. The loader chmods the bundled binary to 0755, performs a SHA-256 integrity check (execution continues even on mismatch with only a log-level change), and spawns the implant as a detached child process via child_process.spawn with detached:true and shell:false, placing it in its own process group to survive the parent Node process.
The delivered binary is RedShell, the native Linux implant of RedC2 4.0 — a C2 framework in active development since at least August 2025 when v2.0 was first documented. RedC2 is marketed by MarlboroMan on Hack Forums at $99.99 with a clearnet website (Red Offsec) as its commercial presence. Version history: v2.0 added RedC2 EXT CLI and Red Agent; v3.0 (January 2026) added multi-operator terminals and macOS beacons; v4.0 (June 1, 2026) introduced the RedShell native Linux implant with in-framework beacon compilation; v4.1 (July 19, 2026) added cross-network shell tunneling; v4.1.3 (August 5, 2026) extended with WSL support and Linux CLI client.
RedShell is a full-featured Linux RAT. Upon execution, it ignores SIGPIPE, double-forks to daemonize, records its working directory, and enters an infinite reconnection loop. It establishes a TLS 1.2+ connection to hardcoded C2 IP 217.60.77.63:8792 (hosted by Miteflux Technologies / ServerExpress, AS203861, 124 City Road, London), with 127.0.0.1:8792 as fallback. TCP uses TCP_NODELAY with aggressive keepalive (1s initial, 3s interval, 5 failures drop). Certificate verification is disabled (SSL_VERIFY_NONE). All command traffic uses a custom three-round XOR + ROR1 (rotate right by 1 bit) cipher over TLS. The implant sends a SECURE_BEACON check-in containing username, hostname, OS/kernel/architecture, root status, public IP (queried via api.ipify.org), and a persistent installation ID (stored at ~/.config/.rsvc, generated from OpenSSL RAND_bytes or timestamp+PID fallback). Commands use length-prefixed binary frames dispatched against 45+ handlers covering system recon, file operations, credential theft, process/account management, and network pivoting.
RedShell supports four persistence mechanisms: systemd user service (~/.config/systemd/user/svc-update.service with Description='System Update Service' and Restart=always), cron (@reboot), ~/.bashrc modification, and XDG autostart entries. A single /persist remove command removes all four. Fileless execution uses memfd_create (syscall 319) for in-memory ELF execution and mmap with executable permissions for shellcode, both via a three-stage staging protocol (membegin/memchunk/memrun). The implant provides SOCKS5 proxy, TCP port forwarding, and cross-network shell tunneling (RC2TUN protocol, Base64 over main C2 channel).
RedC2 ships with Red Agent, an LLM-backed command execution layer accessed via /ra in any beacon terminal. Red Agent translates natural-language intents (e.g., 'dump credentials' or 'locate SSH keys') into ordered chains of beacon commands via keypoint analysis, with full session state visibility and execution authority. This dramatically reduces the skill barrier for effective offensive operations.
Multi-channel exfiltration: bulk data to 217.60.77.63:8060 via chunked HTTP POST (base64-encoded, BIGEXTRACT START/END framing), file downloads from 217.60.77.63:8888, and external uploads to litterbox.catbox.moe via standard HTTPS (with CA validation). Targeted data includes SSH keys (~/.ssh/), browser credential stores, database files, environment variables, and arbitrary filesystem paths. The implant also probes 8.8.8.8:53/UDP to determine its local routing address.
No CVEs have been assigned. Adjacent IP 217.60.77.23 in the same /24 has been flagged for SSH brute-force activity. Trend Micro released IPS signature 47909 (HTTP: Backdoor.Linux.RedShellixo.A Runtime Detection) and published Vision One detection queries. Remediation requires immediate isolation, full credential rotation from a clean machine, blocking 217.60.77.0/24 at perimeter, and auditing npm dependency trees for the 14 packages. Package removal alone is insufficient due to persistence mechanisms.
MITRE ATT&CK techniques used in TL-2026-2099
Exfiltration
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1564.001 Hide Artifacts: Hidden Files and Directories
Persistence
T1037.003 Network Logon Script; T1053.003 Scheduled Task/Job: Cron; T1543.002 Create or Modify System Process: Systemd Service; T1547.015 Login Items
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Execution
T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.007 JavaScript; T1106 Native API; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1219 Remote Access Tools; T1573.001 Encrypted Channel: Symmetric Cryptography
command-and-control
Initial Access
T1195.001 Compromise Software Dependencies and Development Tools
defense-impairment
T1222.002 Linux and Mac Permissions
Credential Access
T1552.004 Private Keys; T1555 Credentials from Password Stores
Affected products and versions in 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor
- npm (OpenJS Foundation) — npm Registry
Vulnerable versions: 14 packages in streak-* and kit-* namespaces at v1.0.0
Fixed in: Packages removed from registry following TrendAI and Amazon Inspector detection - Node.js — npm Ecosystem - All Projects
Vulnerable versions: Any Node.js deployment importing affected packages (direct or transitive)
Fixed in: None - requires manual audit and package removal - Linux — x86_64 Systems
Vulnerable versions: All Linux distributions (target platform for RedShell ELF payload)
Fixed in: N/A - OS-agnostic malware delivery via cross-platform npm ecosystem
Remediation for 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor
Immediate actions
- Isolate affected systems from the network
- Block 217.60.77.0/24 CIDR at network perimeter (ports 8792, 8060, 8888 TCP)
- Uninstall all 14 identified malicious npm packages from every project
- Remove ~/.config/systemd/user/svc-update.service if present and run systemctl --user daemon-reload
- Remove ~/.config/.rsvc if present
- Check crontab for @reboot entries pointing to non-standard paths
- Check ~/.bashrc for suspicious launch commands
- Check ~/.config/autostart/ for suspicious .desktop entries
- Rotate ALL secrets, SSH keys, API tokens, and credentials from a clean, uncompromised machine
- Run Trend Micro IPS signature 47909 to detect RedShellixo payloads
Workarounds
- npm --ignore-scripts does NOT protect against this attack class — the IIFE executes at module import time regardless of hook filtering
- Consider using isolated build environments (containers) with restricted network access for npm install
- Use npm lockfiles with package integrity verification before deployment
- Deploy endpoint detection rules for /bin/sh processes spawned by Node.js (node -- eval or child_process)
Longer-term hardening
- Audit all npm dependency trees for the 14 named packages
- Implement software composition analysis (SCA) with automated malware scanning across all builds
- Deploy runtime detection for unexpected child_process.spawn with detached:true from Node.js modules
- Monitor outbound connections to Miteflux AS203861 IP ranges
- Implement npm package provenance verification (npm attestation) for production dependencies
- Use containerized build environments with restricted egress for npm install operations
- Deploy file integrity monitoring on ~/.config/systemd/user/ for unexpected unit files
Weaknesses (CWE) in 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor
Timeline of 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor
- RedC2 v2.0 first documented — earliest known version of the RedC2 C2 framework, introducing RedC2 EXT CLI client, Red Agent, MongoDB support, SOCKS proxy, and port forwarding.
- RedC2 v3.0 released with multi-operator terminal support, macOS beacons, remote desktop capabilities, and credential extraction modules.
- RedC2 v4.0 released introducing the RedShell native Linux implant with in-framework Linux beacon compilation. Framework advertised on Hack Forums by threat actor MarlboroMan at $99.99.
- RedC2 v4.1 released adding cross-network shell tunneling via Network Map feature.
- streak-metrics-math (first trojanized npm package) published to npm registry (v1.0.0). Detected and tracked as GHSA-57m5-24x9-2xr5.
- RedC2 v4.1.3 released with WSL support and Linux CLI client. streak-calc-math published to npm. Detected as MAL-2026-12114.
- Amazon Inspector detects streak-cache-map as malicious (IN-MAL-2026-016095). Additional packages published to npm registry on or around this date.
- streak-kit-map and streak-map-cache published to npm registry. Tracked as MAL-2026-13519 and GHSA-v2fj-c673-2gjm.
- kit-map-vim published to npm registry. Detected and tracked as MAL-2026-13915 / GHSA-hg96-r46x-6f4w. OSV records show the same RedShell ELF binary hash across all packages.
- TrendAI Research (Aliakbar Zahravi) publishes full reverse engineering report 'Prompting the Payload' detailing the supply chain attack, RedShell technical analysis, C2 protocol reverse engineering, and detection guidance.
- Public disclosure via The Hacker News article. npm registry removes the 14 packages. Trend Micro releases IPS signature 47909 (Backdoor.Linux.RedShellixo.A) for detection.
Sources cited for 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
- Prompting the Payload: How an npm Supply Chain Attack Delivers the RedC2 AI-Powered Linux Implant
- MAL-2026-13403 - streak-cache-map
- MAL-2026-13915 - kit-map-vim
- MAL-2026-13519 - streak-kit-map
- MAL-2026-12114 - streak-calc-math
- MAL-2026-12311 - streak-calc-metrics (OffSeq Radar)
- GHSA-57m5-24x9-2xr5 - streak-metrics-math
- RedC2 Framework - Hack Forums Development Blog
- ossf/malicious-packages - streak-calc-math OSV Entry
Detection coverage for TL-2026-2099
As of 2026-08-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2099 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2099
6 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.