사이버 보안 연구자들이 악성 npm 패키지를 발견해 AI 기반 리눅스 백도어를 배포하고 있음을 확인했습니다.
사이버 보안 연구자들이 기능하는 달력 및 연속성 유틸리티로 위장한 악성 npm 패키지를 발견했습니다. 이 패키지들은 AI 기반의 리눅스 임플란트인 RedC2 4.0을 은밀하게 배포하도록 설계되었습니다. 모듈이 로드될 때, 패키지는 번들된 이진 파일을 찾아 실행 가능으로 표시한 후, 분리된 백그라운드 프로세스로 실행됩니다.
Cybersecurity researchers have discovered malicious npm packages delivering an AI-based Linux backdoor, RedC2 4.0.
Cybersecurity researchers have uncovered a set of trojanized npm packages that disguise themselves as calendar and streak utilities. These packages are engineered to stealthily deliver an AI-powered Linux implant named RedC2 4.0. When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process.