# 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

> TrendAI (Trend Micro) discovered 14 trojanized npm packages masquerading as calendar/streak calculation utilities that deliver the RedC2 4.0 RedShell Linux backdoor. The packages execute on module import via an async IIFE in dist/index.mjs, bypassing npm's --ignore-scripts safeguard, dropping a Linux ELF binary disguised as a native math accelerator. RedC2 4.0 is marketed by threat actor MarlboroMan on Hack Forums at $99.99 and includes the RedShell implant (remote shell, credential theft, SOCKS5 pivoting, fileless execution via memfd_create, four persistence mechanisms) plus Red Agent — an LLM-backed natural-language-to-command translation engine that dramatically lowers the barrier to entry for offensive operations.

- **Published:** 2026-08-21T00:00:00Z
- **Last reviewed:** 2026-08-21T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2099
- **ID:** TL-2026-2099
- **Severity:** CRITICAL
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Actor:** MarlboroMan
- **Detections:** 9 · **IOCs:** 32 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On August 20, 2026, TrendAI Research (Aliakbar Zahravi) published an analysis of 14 trojanized npm packages that deliver the RedC2 4.0 RedShell Linux backdoor — a commercial cross-platform C2 framework marketed on Hack Forums by the threat actor MarlboroMan since June 2026. The packages (all version 1.0.0 except streak-metrics-math which also has 1.0.1) were published to the npm registry between late July and mid-August 2026 under names designed to appear as legitimate calendar streak/date-math utilities: streak-metrics-math, kit-map-vim, streak-map-cache, streak-map-kit, map-streak-kit, streak-cache-map, streak-calc-metrics, streak-calc-math, streak-math-abz, streak-metricsaz, streak-math-metrics, streak-metricazbd, streak-metricsazb, and streak-kit-map. Amazon Inspector and the Open Source Vulnerability (OSV) database issued multiple malware advisories (MAL-2026-12114, MAL-2026-12311, MAL-2026-13403, MAL-2026-13519, MAL-2026-13915 and others).

Each package bundles legitimate date-math implementation alongside a malicious Linux x86_64 ELF binary in dist/ or dist/internal/ directories, named to suggest native math acceleration (math-core.bin, calc-cache.bin, math-calc.bin, calc-math.dat, calc.bin, calc-mapping.bin). All variants share the same SHA-256 hash (4537b1189ce419f1a595cf47216c03f80e9170ce80dad8d9227a1e52f9cb3466), confirming a shared build pipeline. The entry file dist/index.mjs re-exports date helpers from dist/internal/daymath.mjs but contains an async IIFE executing at module load time — not via npm lifecycle hooks. This design specifically bypasses npm's --ignore-scripts safeguard (which only blocks install/uninstall hooks). A single import anywhere in the dependency graph, including transitive imports, triggers payload execution. The loader chmods the bundled binary to 0755, performs a SHA-256 integrity check (execution continues even on mismatch with only a log-level change), and spawns the implant as a detached child process via child_process.spawn with detached:true and shell:false, placing it in its own process group to survive the parent Node process.

The delivered binary is RedShell, the native Linux implant of RedC2 4.0 — a C2 framework in active development since at least August 2025 when v2.0 was first documented. RedC2 is marketed by MarlboroMan on Hack Forums at $99.99 with a clearnet website (Red Offsec) as its commercial presence. Version history: v2.0 added RedC2 EXT CLI and Red Agent; v3.0 (January 2026) added multi-operator terminals and macOS beacons; v4.0 (June 1, 2026) introduced the RedShell native Linux implant with in-framework beacon compilation; v4.1 (July 19, 2026) added cross-network shell tunneling; v4.1.3 (August 5, 2026) extended with WSL support and Linux CLI client.

RedShell is a full-featured Linux RAT. Upon execution, it ignores SIGPIPE, double-forks to daemonize, records its working directory, and enters an infinite reconnection loop. It establishes a TLS 1.2+ connection to hardcoded C2 IP 217.60.77.63:8792 (hosted by Miteflux Technologies / ServerExpress, AS203861, 124 City Road, London), with 127.0.0.1:8792 as fallback. TCP uses TCP_NODELAY with aggressive keepalive (1s initial, 3s interval, 5 failures drop). Certificate verification is disabled (SSL_VERIFY_NONE). All command traffic uses a custom three-round XOR + ROR1 (rotate right by 1 bit) cipher over TLS. The implant sends a SECURE_BEACON check-in containing username, hostname, OS/kernel/architecture, root status, public IP (queried via api.ipify.org), and a persistent installation ID (stored at ~/.config/.rsvc, generated from OpenSSL RAND_bytes or timestamp+PID fallback). Commands use length-prefixed binary frames dispatched against 45+ handlers covering system recon, file operations, credential theft, process/account management, and network pivoting.

RedShell supports four persistence mechanisms: systemd user service (~/.config/systemd/user/svc-update.service with Description='System Update Service' and Restart=always), cron (@reboot), ~/.bashrc modification, and XDG autostart entries. A single /persist remove command removes all four. Fileless execution uses memfd_create (syscall 319) for in-memory ELF execution and mmap with executable permissions for shellcode, both via a three-stage staging protocol (membegin/memchunk/memrun). The implant provides SOCKS5 proxy, TCP port forwarding, and cross-network shell tunneling (RC2TUN protocol, Base64 over main C2 channel).

RedC2 ships with Red Agent, an LLM-backed command execution layer accessed via /ra in any beacon terminal. Red Agent translates natural-language intents (e.g., 'dump credentials' or 'locate SSH keys') into ordered chains of beacon commands via keypoint analysis, with full session state visibility and execution authority. This dramatically reduces the skill barrier for effective offensive operations.

Multi-channel exfiltration: bulk data to 217.60.77.63:8060 via chunked HTTP POST (base64-encoded, BIGEXTRACT START/END framing), file downloads from 217.60.77.63:8888, and external uploads to litterbox.catbox.moe via standard HTTPS (with CA validation). Targeted data includes SSH keys (~/.ssh/), browser credential stores, database files, environment variables, and arbitrary filesystem paths. The implant also probes 8.8.8.8:53/UDP to determine its local routing address.

No CVEs have been assigned. Adjacent IP 217.60.77.23 in the same /24 has been flagged for SSH brute-force activity. Trend Micro released IPS signature 47909 (HTTP: Backdoor.Linux.RedShellixo.A Runtime Detection) and published Vision One detection queries. Remediation requires immediate isolation, full credential rotation from a clean machine, blocking 217.60.77.0/24 at perimeter, and auditing npm dependency trees for the 14 packages. Package removal alone is insufficient due to persistence mechanisms.

## MITRE ATT&CK

- T1195.001 Compromise Software Dependencies and Development Tools
- T1204.002 User Execution: Malicious File
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1059.007 JavaScript
- T1106 Native API
- T1543.002 Create or Modify System Process: Systemd Service
- T1053.003 Scheduled Task/Job: Cron
- T1547.015 Login Items
- T1037.003 Network Logon Script
- T1036.005 Match Legitimate Resource Name or Location
- T1140 Deobfuscate/Decode Files or Information
- T1055 Process Injection
- T1564.001 Hide Artifacts: Hidden Files and Directories
- T1222.002 Linux and Mac Permissions
- T1552.004 Private Keys
- T1555 Credentials from Password Stores
- T1082 System Information Discovery
- T1057 Process Discovery
- T1090.001 Internal Proxy
- T1071.001 Application Layer Protocol: Web Protocols
- T1573.001 Encrypted Channel: Symmetric Cryptography
- T1219 Remote Access Tools
- T1020 Automated Exfiltration

## Sources

- [14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2](https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html)
- [Prompting the Payload: How an npm Supply Chain Attack Delivers the RedC2 AI-Powered Linux Implant](https://www.trendaisecurity.com/en/resources-insights/trendai-security-blog/redc2-ai-powered-linux-implant)
- [MAL-2026-13403 - streak-cache-map](https://osv.dev/vulnerability/MAL-2026-13403)
- [MAL-2026-13915 - kit-map-vim](https://osv.dev/vulnerability/MAL-2026-13915)
- [MAL-2026-13519 - streak-kit-map](https://osv.dev/vulnerability/MAL-2026-13519)
- [MAL-2026-12114 - streak-calc-math](https://osv.dev/vulnerability/MAL-2026-12114)
- [MAL-2026-12311 - streak-calc-metrics (OffSeq Radar)](https://radar.offseq.com/threat/malicious-code-in-streak-calc-metrics-npm-fc34cc2f3d87b23b)
- [GHSA-57m5-24x9-2xr5 - streak-metrics-math](https://github.com/advisories/GHSA-57m5-24x9-2xr5)
- [RedC2 Framework - Hack Forums Development Blog](https://hackforums.net/blog/marlboroman-1)
- [ossf/malicious-packages - streak-calc-math OSV Entry](https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/streak-calc-math/MAL-2026-12114.json)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2099
