By Interestana AI Editorial — AI-drafted, human-overseen. How we report
14 npm Packages Deliver AI-Powered RedC2 Linux Backdoor

Cybersecurity researchers have identified 14 malicious npm packages that were trojanized to deliver a sophisticated artificial intelligence (AI)-powered Linux implant known as RedC2 4.0. These packages, disguised as legitimate calendar and streak utility tools, were discovered by Trend Micro's research arm, TrendAI. The primary function of these trojanized packages is to surreptitiously install and execute the RedC2 4.0 backdoor on targeted Linux systems. Upon installation, the malicious module locates a bundled binary, designates it as executable, and then launches it as a detached background process, ensuring its persistent operation without user intervention. This method allows the attackers to maintain a covert presence and control over the compromised systems. RedC2 4.0 is notable for its advanced command and control (C2) capabilities, which are enhanced by AI. This AI integration allows the malware to potentially adapt its communication strategies, evade detection more effectively, and manage compromised devices with greater sophistication. The AI-assisted C2 mechanism enables the malware to dynamically adjust its behavior based on network conditions, security measures, or specific instructions, making it a more resilient threat. The npm ecosystem, a popular repository for JavaScript packages used in web development, has become a frequent target for supply chain attacks. Attackers exploit the trust developers place in open-source libraries to distribute malware. By compromising legitimate-looking packages, threat actors can reach a wide audience of developers who integrate these packages into their projects, thereby compromising downstream applications and systems. The discovery of these 14 packages highlights the ongoing risks associated with using third-party code and the importance of robust security practices in software development. TrendAI's analysis indicates that the RedC2 4.0 backdoor is designed for persistent access and advanced evasion techniques. The AI component is crucial for its ability to operate stealthily and adapt to defensive measures. The researchers have not disclosed the specific names of the 14 trojanized npm packages to prevent further spread and exploitation, emphasizing the need for vigilance within the developer community. The implications of such AI-enhanced malware extend to the broader cybersecurity landscape, suggesting a future where threats are more intelligent and harder to combat. The use of AI in malware development signifies a significant escalation in cyber warfare capabilities, posing a substantial challenge to existing security infrastructures. Developers are advised to exercise extreme caution when incorporating new or updated npm packages into their projects, including thorough vetting and the use of security scanning tools to detect malicious code.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.