14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 — [https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvZpEOpS6_M3zQlIDwv
What’s new: Researchers have identified 14 trojanized npm packages that deliver the RedC2 4.0 Linux backdoor, which utilizes AI for command-and-control (C2) operations. The malicious packages, which appear to be legitimate calendar and streak utilities, execute the payload upon import without requiring an install hook. The backdoor facilitates various post-exploitation activities, including surveillance and credential theft.
Who’s affected
Any developers or organizations using the affected npm packages, specifically versions of the following:
- streak-metrics-math@1.0.0, 1.0.1
- kit-map-vim@1.0.0
- streak-map-cache@1.0.0
- streak-map-kit@1.0.0
- map-streak-kit@1.0.0
- streak-cache-map@1.0.0
- streak-calc-metrics@1.0.0
- streak-calc-math@1.0.0
- streak-math-abz@1.0.0
- streak-metricsaz@1.0.0
- streak-math-metrics@1.0.0
- streak-metricazbd@1.0.0
- streak-metricsazb@1.0.0
- streak-kit-map@1.0.0
What to do
- Audit your npm package dependencies for the identified trojanized packages.
- Remove any instances of the affected packages from your projects immediately.
- Monitor your systems for any signs of compromise or unusual activity.
- Consider implementing security measures such as package integrity checks and using trusted registries.



