latentbrief
Back to news
Launch2w ago

New AI-Powered Backdoor Discovered in Trojanized npm Packages

The Hacker News1 min brief

In brief

  • Cybersecurity researchers have uncovered a series of malicious npm packages designed to hide an advanced AI-powered backdoor called RedC2 4.0 on Linux systems.
    • These packages, which include names like streak-metrics-math and kit-map-vim, appear legitimate but secretly drop malware during installation.
  • The backdoor uses AI for command-and-control (C2) communication, enabling it to carry out surveillance, credential theft, and other malicious activities across multiple platforms.
  • The malware is delivered through a variety of filenames in the packages, such as math-core.bin or calc-math.dat, which are placed in hidden directories.
  • Once activated, RedC2 4.0 can execute commands, transfer files, and even run payloads directly in memory, making it highly versatile for attackers.
    • This discovery highlights the growing sophistication of cyber threats, particularly those leveraging AI for evasive operations.
  • Developers and users are urged to verify package authenticity and update their npm dependencies immediately to avoid infection.

Terms in this brief

RedC2 4.0
An advanced AI-powered backdoor discovered in malicious npm packages. Once installed, it can execute commands, transfer files, and run payloads directly in memory, enabling surveillance and credential theft across multiple platforms. The use of AI for command-and-control communication makes it highly sophisticated and evasive.

Read full story at The Hacker News

More briefs