Malicious npm Packages Deploy Linux Backdoor for Network Intrusion
Cybersecurity researchers have uncovered a supply-chain campaign involving trojanized npm packages that secretly install the RedShell Linux implant, allowing attackers to transform compromised systems into SOCKS5 proxies for internal network access.
The campaign uses legitimate-looking calendar and date-calculation utilities to hide malicious functionality, demonstrating how attackers can abuse software dependencies without relying on traditional npm installation scripts.
Researchers from TrendAI identified 14 malicious npm packages, including names such as streak-metrics-math, kit-map-vim, streak-map-cache, and streak-calc-math.
Although these packages provide the advertised functionality, they also contain a hidden ELF binary disguised as a native performance component. This binary installs the RedC2 4.0 Linux implant.
Supply Chain Attack Activates Malware Through Package Imports
The attackers avoided common npm abuse techniques by not using preinstall or postinstall scripts.
Instead, the malicious dist/index.mjs file automatically launches an initialization routine when the package is imported.
The script locates the embedded binary, changes its permissions, verifies its SHA-256 hash and executes it as a detached process.
Because the malware runs during package usage rather than installation, security controls such as npm’s --ignore-scripts protection may not prevent infection.
After execution, RedShell disconnects from the original Node.js process and continues operating independently in the background.
RedShell Provides Remote Access and Network Pivoting
The implant establishes an encrypted command-and-control connection to an attacker-controlled server while using additional obfuscation techniques to hide communications.
Its most dangerous capability is built-in network pivoting.
Attackers can activate a SOCKS5 proxy on the compromised Linux host, allowing them to route traffic through the infected machine and access internal systems that are not directly exposed to the internet.
The malware also supports TCP forwarding, enabling attackers to connect from the compromised host to internal services, including:
- SSH servers
- Databases
- Administrative panels
- Other lateral movement targets
This allows a compromised development server, container host, or build system to become a gateway into a larger environment.
AI-Assisted Control Expands Attack Capabilities
RedC2 also includes Red Agent, an AI-powered command layer designed to simplify post-compromise operations.
According to the framework documentation, the feature can convert natural-language instructions into sequences of commands, helping operators perform activities such as reconnaissance, file discovery and credential collection.
The RedShell implant supports multiple malicious functions, including:
- Remote shell execution
- Reverse shell access
- SSH key theft
- Browser credential collection
- Database discovery
- Fileless execution
- Process manipulation
- Persistence mechanisms
Attackers can maintain access through cron jobs, .bashrc modifications, user-level systemd services and XDG autostart entries.
Defenders Urged to Investigate npm Dependencies
Organizations using npm packages should review both direct and transitive dependencies for the identified malicious packages.
Security teams should investigate:
- Unexpected ELF binaries inside Node.js package directories
- Suspicious permission changes followed by detached processes
- New cron jobs or systemd services
- Unauthorized .bashrc modifications
- Unknown Linux listeners exposing SOCKS or forwarding services
- Unusual outbound connections from development systems
Network monitoring should also focus on suspicious connections to known RedShell infrastructure and abnormal traffic patterns from Linux hosts.
The campaign highlights the growing risk of software supply-chain attacks, where attackers hide advanced malware inside trusted development dependencies.
By compromising a single package, threat actors can gain persistent access, move through internal networks and turn legitimate infrastructure into a platform for further attacks.
