4 min read
News Brief Trend Micro found 14 npm packages hiding a Linux backdoor that connects to RedC2 4.0, a commercial C2 kit whose 'Red Agent' turns plain-English commands into post-exploitation actions.
Trend Micro found 14 npm packages hiding a Linux backdoor that connects to RedC2 4.0, a commercial C2 kit whose 'Red Agent' turns plain-English commands into post-exploitation actions.
Unit 42 researchers found five malicious skills on ClawHub that slipped past automated scanners, delivering AMOS malware and running agentic financial scams. The AI agent skill marketplace is the new npm — and it has the same supply chain problem.
Fifteen malicious IDE plugins on the JetBrains Marketplace, posing as AI coding assistants powered by DeepSeek and OpenAI, have been silently exfiltrating AI API keys since October 2025. Researchers say the plugins are still live and the install count has passed 70,000.