Researchers discovered 14 trojanized npm packages, disguised as calendar and productivity-streak utilities, that silently install RedC2 4.0, a Linux implant sold on underground forums. The malware bundles an LLM-backed component that converts natural-language attacker intent, such as “dump credentials” or “locate files,” into automated command chains, alongside a cross-platform command-and-control and proxy framework for network pivoting. No install script or hook is required; a single transitive import executes the payload. The packages were publicly disclosed around August 21, 2026.