Fake npm Calendar Tools Hid an AI-Powered Linux Backdoor

Researchers found 14 booby-trapped packages on the popular open-source library npm, each quietly installing a remote-control tool called RedC2 4.0 on Linux machines.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
A developer's workstation with a code editor showing package dependencies and terminal windows with security warnings, with red alert indicators on the screen
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Researchers at Trend Micro's TrendAI unit found 14 malicious packages on npm, the code library used by millions of JavaScript developers.
  • The packages pretended to be calendar and habit-tracker helpers but installed a hidden Linux backdoor called RedC2 4.0.
  • RedC2 4.0 uses an AI model to help its operators write commands and analyse stolen data.
  • On install, the packages quietly launched a bundled program in the background, giving attackers remote control of the machine.
  • Developers who installed any of the flagged packages should treat the affected systems as breached and rotate credentials.

A fresh batch of poisoned developer packages has turned up on npm, the giant open-source code library that JavaScript programmers pull from every day. On the surface they looked like small helpers for calendars and daily streaks. Underneath, they were shipping a Linux backdoor with an AI assistant bolted on.

The find comes from TrendAI, the AI-security team at Trend Micro, and was first reported by The Hacker News. TrendAI counted 14 trojanized packages: packages that carry hidden malicious code inside otherwise normal-looking software. We first covered RedC2 on 21 August 2026, and this latest campaign shows the tooling has been updated and redeployed quickly.

What exactly did the packages do?

Once a developer installed one, the package quietly ran a hidden program stored inside it. That program, RedC2 4.0, is a backdoor: software that lets a remote attacker send commands to your computer as if they were sitting at the keyboard.

"When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process," TrendAI wrote. The package finds the malicious file it brought with it, gives it permission to run, and starts it where the user won't notice.

The target is Linux, the operating system that runs most cloud servers and the machines behind a huge share of the internet's plumbing.

Why does the "AI" part matter?

RedC2 4.0 plugs into a large language model, the kind of AI system that powers chatbots. Attackers can ask it to draft the next command, summarise what it found on a hacked machine, or sift through stolen files faster than a human operator could.

This is less a shiny new attack and more a productivity upgrade for criminals. The break-in method here, sneaking bad code into a trusted package repository, is a classic supply-chain attack: tampering with an ingredient at the factory rather than poisoning one restaurant's dish. Npm has been a recurring target; our 3 August report on fake Alibaba packages found 18 similarly trojanized packages using the same registry.

What's genuinely new is that the operator on the other end has a co-pilot. Less skilled attackers can now run campaigns that used to need an experienced hand.

Who is at risk?

Mostly developers and the companies that employ them. A programmer who installed one of the tainted packages on a Linux workstation or build server likely gave attackers a foothold there, and possibly deeper into whatever that machine could reach: source code, cloud keys, internal systems.

Ordinary users of finished apps aren't the direct target. The risk to the public is second-hand: a poisoned developer machine can end up shipping poisoned software downstream, or leaking customer data.

What should teams do now?

Check your install logs against the list Trend Micro published. Any Linux machine that ran one of the 14 packages should be treated as broken into. That means rebuilding it, rotating access tokens, and hunting for outbound connections to unfamiliar servers.

Beyond this incident, the fix is boring and effective: pin exact package versions, review new dependencies before adding them, and run builds inside throwaway environments so a malicious install script can't reach anything valuable.

Npm supply-chain poisoning isn't going away. An AI-assisted backend makes it cheaper to operate. Expect more of it.

© 2026 Threat Vectr