Supply-Chain Polyglot — RedC2 4.0 & the 24-Package npm Campaign Hide a Dropper That Is Both Script and ZIP
Polyglot (dual-format) smuggling is a quiet supply-chain favorite, and on 2026-08-25 it ran alongside CISA adding CVE-2026-21962 (Oracle WebLogic, CVSS 10.0) to its KEV catalog — yet perimeter patches do nothing for the stage-2 loaders that already reach developer endpoints. In August 2026, two campaigns weaponized packaging formats: 24 malicious npm packages that pull second-stage payloads from unpkg mirrors behind fake Cloudflare CAPTCHA pages (The Hacker News, 2026-08-24), and the RedC2 4.0 framework that backdoors Linux developers through trojanized npm releases (iThome, 2026-08). An attacker crafts ONE artifact that parses as BOTH a genuine shell script AND a valid ZIP (npm) archive, so any control keyed to a single format — extension, magic bytes, or an 'is this a script?' heuristic — sees only the benign half and lets the disguised loader through. This demo reproduces the trick safely: the malicious sample is a calculator-only Bash script prepended to a real ZIP, so the file is simultaneously executable as a script AND openable as an archive; if launched, it only opens the calculator — no real payload, no network, no destruction. MetaDefender FileType Engine fingerprints the file's actual content instead of trusting one declared format, reports every format it genuinely matches (script + archive), and blocks it before execution — the same control that would neutralize the polyglot npm droppers behind the 24-package campaign and RedC2 4.0.
Attack Technique
Polyglot file valid as both a shell script and a ZIP archive (T1036.005)
MITRE ATT&CK
T1036.005 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗