The RedC2 packages appeared on npm as useful calendaring and day-tracking tools, but they hid a backdoor for Linux. Including them in a project was enough to launch RedShell, giving remote operators access to the shell, files, and credentials.

The discovery, attributed to TrendAI Research and reported by The Hacker News, found 14 modified RedC2 packages that provided normal functionality but also carried the RedShell Linux beacon, part of the RedC2 4.0 framework.
See also: Malicious arrayref version infects Rust projects at compile time
How RedC2 packages work
RedC2 packages do not rely on any optional installation hook or require the developer to call a specific function. The loader is located in dist/index.mjs and is invoked when the module is loaded with import, even if the package arrived in the project as an indirect dependency. Thus, a normal deployment process can launch the code without any obvious message.
The payload file appears under different names, such as math-core.bin, math-calc.bin, calc-math.dat , and calc-cache.bin, inside the dist or in dist/internal. Despite the disguise as a math accelerator, the content is the same RedShell beacon. The RedC2 packages continue to offer the promised date helper functions, making it easier for malicious behavior to go undetected.

What RedShell can do on Linux
After booting, the RedC2 packages let the beacon collect basic system information and send an initial control message to the command and control server. It then waits for instructions, executes them via /bin/sh , and returns the results to the operator. This function turns a deployment dependency into a permanent entry point for subsequent actions.
Features include interactive shell, system and network search, file operations, SSH key and credential collection from browsers, persisting access, and ELF execution in memory. SOCKS5 proxying and network migration are also supported, increasing the risk for workstations and servers used in CI/CD chains.
See also: ChainDrop worm steals credentials by infecting npm packages
The role of RedC2 4.0 and Red Agent
RedC2 4.0 is advertised as a cross-OS framework for Windows, macOS, and Linux. It includes file transfers, loading additional payloads, multiple beacons, network imaging, tunneling, and in-memory code execution. RedC2 EXT extends the commands from the command line, while Red Agent uses a large language model to convert natural language instructions into command sequences.
The use of AI does not change the basic technique of the incident, but it does reduce the barrier for operators who do not know all the commands of a beacon. TrendAI notes that the tool is promoted by Red Offsec and does not attribute this particular campaign to a state group. Therefore, the report should be read as documentation of malicious software distribution, not as evidence of a specific geopolitical origin.

Controls for development and security teams
For RedC2 packages, development teams should check lockfiles, install history, and recent changes to npm dependencies. Pay particular attention to the dist and dist/internal, as well as the filenames used as wrappers. Looking for unknown processes starting from Node.js and unexpected outbound connections can help with initial detection.
If a suspicious package was loaded on a workstation or pipeline, the system should be isolated, logs checked, and SSH keys, npm tokens, and other secrets changed from a clean environment. The installation should be repeated from known safe lockfiles, with integrity checks and process permissions restricted. These recommendations are practical defense measures and do not constitute an official TrendAI action plan.
See also: StubMaker: RubyGems packages steal developer data
In continuous integration environments, the import of a dependency can be performed on temporary execution machines, in test environments, and in production stages. Therefore, the control should not be limited to the developer's computer: it is necessary to record the files that the builds produce, restrict output to the internet, and verify the processes that are started during installation.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The case illustrates why software supply chain security is not limited to choosing a well-known name from npm. Imports must be controlled, dependencies limited to the bare essentials, and every change tracked. For teams using these packages, the safe course of action for RedC2 packages is to immediately remove them, investigate possible execution, and rotate any secrets that may have been exposed.
