Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0.”When the module loads, it”¯locates”¯the bundled binary, marks it executable, and launches it as a detached background process,” TrendAI, Trend Micro’s
First seen on thehackernews.com
Jump to article: thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html
![]()

