LIVE · cybersecurity feed
Live wire
CVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on HostCISA orders feds to patch actively exploited TrueConf Server flawsCVE-2026-69836 · Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
npmhigh

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

Researchers have identified 14 malicious npm packages disguised as calendar and streak utilities that deliver a sophisticated Linux backdoor known as RedC2 4.0. These packages, once imported, stealthily execute a Linux implant that communicates with a command-and-control server for post-exploitation activities. The RedC2 framework, marketed as a cross-platform toolkit, features AI-assisted capabilities for orchestrating complex intrusions using natural language commands.

zeroday.news ·

A recent report indicates that security researchers have uncovered 14 malicious npm packages designed to deploy a Linux backdoor identified as RedC2 4.0. These packages were reportedly masquerading as legitimate utilities related to calendar and streak tracking functionalities within the npm ecosystem. The discovery highlights an ongoing threat vector targeting developers and systems reliant on open-source package managers.

Upon successful integration into a project, these trojanized npm packages are said to execute a Linux implant. This implant establishes communication with a command-and-control (C2) server, enabling post-exploitation activities. The nature of these activities typically ranges from data exfiltration and further system compromise to establishing persistent access within the compromised environment.

The backdoor itself is identified as RedC2 4.0, described as a sophisticated Linux implant. This version is part of a broader RedC2 framework, which is reportedly marketed as a cross-platform toolkit for intrusion operations. The framework's capabilities are noted to include AI-assisted features, allowing for the orchestration of complex intrusions through natural language commands, which could potentially streamline attacker operations and enhance their adaptability.

The npm ecosystem, like other public package repositories, is a frequent target for supply chain attacks. Attackers often upload malicious packages with names similar to popular legitimate libraries, or introduce new packages that appear benign but contain hidden malicious code. Developers who integrate these packages into their projects unknowingly introduce vulnerabilities or backdoors into their applications and infrastructure.

Mitigation strategies for this class of threat typically involve rigorous supply chain security practices. This includes scrutinizing package dependencies, utilizing software composition analysis (SCA) tools to detect known vulnerabilities and malicious packages, and implementing strong access controls. Developers are also advised to verify the authenticity and reputation of package maintainers before incorporating new libraries into their projects.

The incident underscores the persistent challenge of securing the software supply chain, particularly within the open-source community. The reported use of AI-assisted capabilities within the RedC2 framework suggests an evolving landscape where threat actors are leveraging advanced technologies to enhance their operational efficiency and the complexity of their attacks. This trend necessitates continuous vigilance and adaptation in defensive strategies.

npmsupply chain attackmalwarebackdoorredc2
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

AWS Security makes an inscrutable choice

Quarantining leaked credentials is not good enough

cloud security

Cloudflare Launches Bot Preference Sync for AI Traffic Management

Cloudflare has introduced Bot Preference Sync, a new feature designed to simplify the management of AI bot traffic. This tool automatically updates a website's robots.txt file to align with the user's AI bot configuration settings. The goal is to prevent discrepancies between stated preferences and enforced rules, ensuring better control over how AI crawlers access and use website content.

ai

Say it once: introducing Bot Preference Sync

Cloudflare's new Bot Preference Sync automatically aligns your robots.txt file with your AI bot policies for Search, Agent, and Training. Easily manage which bots access your content without maintaining static files.

CVE-2024-3094high

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

Attackers are increasingly targeting the software development lifecycle (SDLC) supply chain by compromising developer tools, CI/CD pipelines, and open-source packages. Recent attacks like the ChainDrop npm worm demonstrate sophisticated methods to steal credentials, backdoor developer environments, and propagate malware. Securing the SDLC requires a shift from reactive code scanning to strict execution control and continuous visibility across developer endpoints, build pipelines, and cloud runtimes.

patch

Friday Squid Blogging: Neon Flying Squid

The neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion. They were probably neon flying squid (Ommastrephes bartramii),

security

Lawmakers call for investigation into impact of CISA staffing cuts

Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.