M-RED-TEAM is a malware framework name observed in a July 2026 software supply-chain compromise affecting multiple AsyncAPI npm packages. Recovered stage-3 payload source identified itself as M-RED-TEAM v6.4 and also used Miasma branding across artifacts, configuration, persistence mechanisms, and identity paths. The observed intrusion chain used malicious code embedded in normal runtime modules so that importing a compromised package triggered execution, followed by retrieval of an encrypted Node.js loader from IPFS, deployment of a detached background implant, and establishment of host persistence. The deployed implant functioned as a persistent remote access backdoor. It generated a public/private keypair on first run, prevented duplicate execution with a lock mechanism, beaconed at regular intervals over HTTP, and supported signed and encrypted command traffic with a plaintext fallback mode. It enabled arbitrary shell command execution through child process invocation and included update mechanisms that could pull new payloads from operator-supplied content identifiers or polling channels. Persistence methods covered major desktop/server platforms, including shell startup modification on macOS, autorun registration on Windows, and user-level systemd service creation on Linux. The recovered codebase also contained additional capabilities for credential harvesting, propagation, evasion, mutation, AI-tool poisoning, and deadman-switch behavior, although those features were disabled in the analyzed build. Because attribution in this case is explicitly inconclusive, M-RED-TEAM should be treated as a payload or framework designation rather than a confidently attributed threat actor identity. Available evidence does not establish whether the operators behind the AsyncAPI compromise were the original developers or habitual users of M-RED-TEAM, or whether the branding reflected code reuse, imitation, or deliberate false-flagging.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.