Posted on 08/24/2026 3:34:11 PM PDT by BenLurkin
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0.
"When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process," TrendAI, Trend Micro's enterprise cybersecurity business, said in a report published Thursday. "No install hook function call is needed; a single import anywhere in the dependency graph, even a transitive one, is enough to execute the payload."
...
What's notable about these packages is that they are functional and offer the promised functionality. But beneath that garb of date utilities is code designed to drop a Linux backdoor by framing it as a native math accelerator. The name of the file varies across the packages: math-core.bin, math-calc.bin, calc-math.dat, calc-cache.bin, calc.bin, calc-mapping.bin.
It's located either directly within the "dist/" or under "dist/internal/," but what it contains is the same: the RedShell Linux beacon for RedC2 4.0 that communicates with a remote Windows or Linux server to facilitate post-exploitation activities on the compromised host.
(Excerpt) Read more at thehackernews.com ...
Dear FRiends,
We need your continuing support to keep FR funded. Your donations are our sole source of funding. No sugar daddies, no advertisers, no paid memberships, no commercial sales, no gimmicks, no tax subsidies. No spam, no pop-ups, no ad trackers.
If you enjoy using FR and agree it's a worthwhile endeavor, please consider making a contribution today:
Click here: to donate by Credit Card
Or here: to donate by PayPal
Or by mail to: Free Republic, LLC - PO Box 9771 - Fresno, CA 93794
Thank you very much and God bless you,
Jim
the AI they’re sneaking in everywhere is wearing out our computers faster and we can’t afford to buy new or even old ones
With news like this, I'm gonna take tomorrow off.
Great, so nonw Linux needs an antivirus program
I can’t figure out why computers would need those things.
“Trojanized”?
A reference to that giant horse the Greeks used to sneak into Troy.
Ah yes. Hollowed and filled with the smuggled enemy.
I just usually don’t see it used as an active verb, but, here we are. Earth remains on it’s axis!
is the average user susceptible to this? is it in an update?
No. You’ll be fine as long as you stay away from node.js/npm. npm has been a vector for bad packages for a long time, and they seem either unwilling or unable to do anything about it.
i dont even know what npm is- I’m not real savvy on linux-
Sure package managers are giant security holes but they save sooo much time. ¯\_(ツ)_/¯
I read the article twice and got:
1. it creeps in disguised as math-related files,
2. there’s versions for Linux, Microsoft and Apple,
3. Chrome-based browsers are a primary target,
4. the writer told us jack squat on how to deal with it.
But 20 years after leaving I.T. work I’m not up as I’d like to be. Any suggestions other than “don’t use the internet”?
too small. can’t read it.
Yikes. Sigh.
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.