14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 — [https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvZpEOpS6_M3zQlIDwv

14-trojanized-npm-packages-drop-redc2-40-linux-backdoor-with-ai-assisted-c2

What’s new: Researchers have identified 14 trojanized npm packages that deliver the RedC2 4.0 Linux backdoor, which utilizes AI for command-and-control (C2) operations. The malicious packages, which appear to be legitimate calendar and streak utilities, execute the payload upon import without requiring an install hook. The backdoor facilitates various post-exploitation activities, including surveillance and credential theft.

Who’s affected

Any developers or organizations using the affected npm packages, specifically versions of the following:

  • streak-metrics-math@1.0.0, 1.0.1
  • kit-map-vim@1.0.0
  • streak-map-cache@1.0.0
  • streak-map-kit@1.0.0
  • map-streak-kit@1.0.0
  • streak-cache-map@1.0.0
  • streak-calc-metrics@1.0.0
  • streak-calc-math@1.0.0
  • streak-math-abz@1.0.0
  • streak-metricsaz@1.0.0
  • streak-math-metrics@1.0.0
  • streak-metricazbd@1.0.0
  • streak-metricsazb@1.0.0
  • streak-kit-map@1.0.0

What to do

  • Audit your npm package dependencies for the identified trojanized packages.
  • Remove any instances of the affected packages from your projects immediately.
  • Monitor your systems for any signs of compromise or unusual activity.
  • Consider implementing security measures such as package integrity checks and using trusted registries.

Sources