Security1 distinct publisher2 min readUpdated
Trend Micro says the loader fires when the module is imported, not when it is installed. That moves the only workable control from install-hook scanning to knowing every name in the resolved tree.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The useful asymmetry in this indicator set is that the payload name moves and the loader does not. Trend Micro lists six filenames for the bundled binary (math-core.bin, math-calc.bin, calc-math.dat, calc-cache.bin, calc.bin, calc-mapping.bin) and two places it can sit, either dist/ or dist/internal/ [7][8]. The delivery path is identical across the set: dist/index.mjs, which re-exports the date helpers and starts the implant as the module loads [6]. Hunting on a filename covers part of the collection; hunting on an entry file that marks a bundled binary executable and launches it detached covers all of it [18][5].
Read the version strings next. Every listed package sits at 1.0.0, with one exception also published at 1.0.1, which comes to fifteen artifacts across fourteen names [2][14]. None of them is a hijacked update to an established library [16], so the reflexes built for that case have nothing to grip: no known-good earlier release to pin back to, no maintainer history in which a change looks out of place. The registry entry was hostile from its first publish.
The naming argues against blocklists as well. Twelve of the fourteen begin with streak-, and the rest reshuffle the same small token set of map, kit, cache, calc, math and metrics [15]. That is the output of a generator, and a list of fourteen strings is a snapshot of it. The control that still works against the next batch answers a different question: what is actually in the resolved tree, at every depth, and what in it has no reason to be there.
Which is where the report's own sentence does the work. No install hook function call is needed, and a single import anywhere in the dependency graph, even a transitive one, is enough to execute the payload, according to TrendAI [4]. The first host is rarely the point. The framework on the other end advertises host-to-host tunneling, multi-beacon operation and in-memory execution of BOFs and .NET assemblies [19], which is tooling for leaving the machine you landed on, and a Linux build agent that resolved one of these names without declaring it is interesting mostly for what it can reach.
The seller's lineage is not hidden: 2.0 in August 2025, 3.0 in January, and 4.0 advertised by a threat actor called MarlboroMan on Hack Forums in early June 2026, with the RedShell Linux beacon new in that version [10][11]. Two major releases inside ten months [17]. Red Offsec's terms of service prohibit unauthorized computer access and hacking without permission [13], which describes the seller's paperwork and nothing about the fourteen packages.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
TrendAI: "No install hook function call is needed; a single import anywhere in the dependency graph, even a transitive one, is enough to execute the payload."
TrendAI: "When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process."
Delivery is handled by the package entry file dist/index.mjs, acting as a trojan loader that re-exports the date helpers and launches the bundled implant as soon as the module loads, with no install hook and no exported function required, according to researcher Aliakbar Zahravi.
Trend Micro's enterprise cybersecurity business, TrendAI, published a report on Thursday describing trojanized npm packages that masquerade as working calendar and streak utilities while delivering an AI-powered Linux implant dubbed RedC2 4.0.
The identified packages are streak-metrics-math (1.0.0 and 1.0.1), kit-map-vim, streak-map-cache, streak-map-kit, map-streak-kit, streak-cache-map, streak-calc-metrics, streak-calc-math, streak-math-abz, streak-metricsaz, streak-math-metrics, streak-metricazbd, streak-metricsazb and streak-kit-map, all at 1.0.0 except where noted.
The packages are functional and provide the promised date-utility functionality, while the code beneath drops a Linux backdoor framed as a native math accelerator.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific indicators, single vendor source
The technical record is concrete and checkable: fourteen named packages with pinned versions, a constant loader path, six binary filenames across two directories, and an enumerated beacon command surface, attributed to a named researcher in a dated vendor report. But it is one report relayed by one outlet, with no independent confirmation, no registry-side data and no C2 network indicators, which caps the score well short of corroborated.
Tooling shipping and sold; impact unmeasured
There is real evidence of supply and distribution - packages actually published to npm, a framework on sale at $99.99 with four releases in about a year - but nothing on the demand or damage side: no download counts, no dependent projects, no victim or infection data, and no statement on takedown. Adoption is therefore measurable only as attacker-side activity.
Mechanism solid, reach and AI framing oversold
The core technical finding is understated rather than hyped - import-time execution genuinely defeats install-hook controls, and the reporting spells out why. The overstatement sits at the edges: 'AI-powered' and 'lowering the barrier to entry' rest on a marketed LLM wrapper with no demonstrated effect, and a fourteen-package count with no download, dependent or victim data invites readers to infer scale that the evidence does not establish.
Vendor threat research plus actor self-marketing
Both ends of the record are incentivized. The findings come from a commercial security vendor whose threat research supports its detection products, and the framework's capability claims, evasion positioning and 'red team professionals' terms of service are the seller's own promotional and liability-shielding language, reproduced in the article. The trade outlet adds a volume-driven incentive to relay vendor research quickly.
Mechanism credible, exposure unknown
Confidence is moderate: the mechanism and indicator-level claims are internally consistent, doubly quoted and specific enough to verify, so the technical core is likely sound. It is held down by single-source dependence, absent registry and victim telemetry, an unresolved link between the npm campaign operator and the tool's seller, and no takedown status, all of which leave the story's practical severity undetermined.
build
The npm audit that works because it never installs the package1 distinct publisher
build
Claude Code's new default is a confession: the approval prompt was never a control1 distinct publisher
product
Cloudsmith's cooldown policies make delay a control, and that makes it your decision1 distinct publisher
security
A manifest edit, not a code edit: North Korea backdoored three Rust crates via typosquat1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 21, 2026