Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. "When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process," TrendAI, Trend Micro's enterprise cybersecurity business, said in a report published Thursday. "No install hook function call is needed; a single import anywhere in the dependency graph, even a transitive one, is enough to execute the payload." The list of identified packages is below - - streak-metrics-math@1.0.0,1.0.1 - kit-map-vim@1.0.0 - streak-map-cache@1.0.0 - streak-map-kit@1.0.0 - map-streak-kit@1.0.0 - streak-cache-map@1.0.0 - streak-calc-metrics@1.0.0 - streak-calc-math@1.0.0 - streak-math-abz@1.0.0 - streak-metricsaz@1.0.0 - streak-math-metrics@1.0.0 - streak-metricazbd@1.0.0 - streak-metricsazb@1.0.0 - streak-kit-map@1.0.0 What's notable about these packages is that they are functional and offer the promised functionality. But beneath that garb of date utilities is code designed to drop a Linux backdoor by framing it as a native math accelerator. The name of the file varies across the packages: math-core.bin, math-calc.bin, calc-math.dat, calc-cache.bin, calc.bin, calc-mapping.bin. It's located either directly within the "dist/" or under "dist/internal/,", but what it contains is the same: the RedShell Linux beacon for RedC2 4.0 that communicates with a remote Windows or Linux server to facilitate post-exploitation activities on the compromised host. "Delivery is handled by the package entry file, dist/index.mjs, which acts as a trojan loader," security researcher Aliakbar Zahravi said. "It re-exports the date helpers and launches the bundled implant as soon as the module loads, with no install hook and no exported function required." RedC2 4.0, marketed on cybercrime forums as a cross-platform toolkit for Windows, macOS, and Linux, offers surveillance, credential theft, payload loading, and mass-operation capabilities. The version was advertised by a threat actor named "MarlboroMan" on