14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor
This digest was compiled by AI from multiple sources — links to the originals are below.

Trend Micro researchers identified 14 trojanized npm packages that deliver the RedC2 4.0 Linux backdoor. The packages masquerade as calendar and streak utilities and execute the implant upon import without an install hook. RedC2 4.0 was advertised on Hack Forums in June 2026 by a threat actor named MarlboroMan.
Key Facts
- 14 npm packages were identified as trojanized, with names such as [email protected] and [email protected].
- The packages drop a Linux backdoor called RedShell, which is the beacon for RedC2 4.0.
- RedC2 4.0 was advertised on Hack Forums in early June 2026 by a threat actor named MarlboroMan.
- The RedShell Linux beacon was introduced in version 4.0 of RedC2.
Trojanized Package Delivery
The packages are functional and offer the promised calendar and streak utilities. Beneath that functionality, code drops a Linux backdoor framed as a native math accelerator. The file name varies across packages: math-core.bin, math-calc.bin, calc-math.dat, calc-cache.bin, calc.bin, calc-mapping.bin. The file is located either directly within the dist/ directory or under dist/internal/. The package entry file dist/index.mjs acts as a trojan loader, re-exporting date helpers and launching the bundled implant as soon as the module loads.
RedC2 4.0 Capabilities
RedC2 4.0 is marketed on cybercrime forums as a cross-platform toolkit for Windows, macOS, and Linux. The framework supports terminal access, file transfer, staged payload delivery, data collection, multi-beacon operation, network visualization, host-to-host tunneling, and in-memory execution of Beacon Object Files, .NET assemblies, and shellcode. Version 3.0 of RedC2 was sold in January 2026, and version 2.0 was released in August 2025. The RedShell Linux beacon was introduced in version 4.0.
1 source
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor



