Threat Intelligence

AI-Powered Backdoor Hidden in Fake npm Packages Targets Linux Systems

The Hacker News · 22 Aug 2026
Key Takeaway Before installing any npm package, verify its source, check for recent security reports, and avoid unnecessary or unfamiliar dependencies in your business software.

Security researchers have uncovered 14 trojanized npm packages posing as ordinary calendar and 'streak' tracking utilities. Once installed, these packages quietly deploy a hidden binary, mark it as executable, and run it as a background process—giving attackers a foothold on Linux systems without the victim's knowledge.

The malicious payload, dubbed RedC2 4.0, is notable for its use of AI-assisted command-and-control (C2) capabilities, allowing attackers to manage compromised systems more efficiently. Because the packages appear to offer legitimate functionality, developers and businesses using npm to manage software dependencies may unknowingly introduce this backdoor into their environments simply by installing what looks like a harmless utility.

This incident is part of a broader trend of attackers targeting open-source software supply chains, where trust in widely used package repositories like npm is exploited to distribute malware at scale. For small businesses that rely on developers or third-party tools built with npm packages, this highlights the importance of vetting dependencies carefully before deployment.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.