Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: redc2 (1 article)Clear

Fake npm calendar tools drop an AI-assisted Linux backdoor on import

Trend Micro found 14 malicious npm packages that pose as working calendar and streak utilities while secretly installing a Linux backdoor from the commercial RedC2 4.0 toolkit. The packages function as advertised, but on load they locate a bundled binary disguised as a math accelerator, mark it executable, and run it as a detached background process. No install script is needed, so a single import anywhere in the dependency graph, even a transitive one, triggers execution. RedC2 is sold on criminal forums as an evasion-focused command-and-control framework with surveillance, credential theft, tunneling, in-memory payload execution, and AI-assisted command features. It shows how import-time execution keeps making package registries an easy delivery route.

Check
Audit npm dependencies, including transitive ones, for the malicious calendar packages and any bundled binaries, and remove them, since simply importing one runs the backdoor without an install script.
Affected
Developers and systems that installed the trojanized npm calendar packages; importing one anywhere in the dependency tree drops and runs a RedC2 Linux backdoor with surveillance, credential theft, and remote-control capabilities.
Fix
Pin and vet dependencies, watch for packages that bundle binaries or spawn detached processes on import, use lockfiles and isolated builds, and monitor developer and CI hosts for unexpected outbound connections.