14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

2026-08-22T01:24:05Za57b98e526760aaebf383b922336c81d09d63b1fe5742ac467d9f2671bd04c91
CVE-2026-19478CVE-2026-32475CVE-2026-73570AI-assisted attacksAndroid malwareDoS amplificationGitLabLinux malwareNetScalerOAuth abuseRust cratesSiemens PLCWordPressZimbraactive exploitationauthentication bypassbanking trojanbrowser extensionscommand injectioncritical infrastructurecryptocurrency theftidentity hijackingnpmremote code executionspywaresupply chain attackvehicle head unitsvulnerability

What happened

A threat-intelligence digest covering active exploitation, critical vulnerabilities, malware campaigns, software supply-chain compromises, identity hijacking, AI-assisted attacks, and denial-of-service techniques. The most urgent items include actively exploited GitLab and Zimbra vulnerabilities, critical NetScaler and Elementor Pro flaws, a sandbox escape in isolated-vm, and malware targeting Linux systems, Android devices, vehicle head units, browsers, and cryptocurrency wallets.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
a57b98e526760aaebf383b922336c81d09d63b1fe5742ac467d9f2671bd04c91
Enrichment time
2026-08-22T01:24:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.