M-RED-TEAM is a malware framework name observed in a July 2026 software supply-chain compromise affecting multiple AsyncAPI npm packages. Recovered stage-3 payload source identified itself as M-RED-TEAM v6.4 and also used Miasma branding across artifacts, configuration, persistence mechanisms, and identity paths. The observed intrusion chain used malicious code embedded in normal runtime modules so that importing a compromised package triggered execution, followed by retrieval of an encrypted Node.js loader from IPFS, deployment of a detached background implant, and establishment of host persistence. The deployed implant functioned as a persistent remote access backdoor. It generated a public/private keypair on first run, prevented duplicate execution with a lock mechanism, beaconed at regular intervals over HTTP, and supported signed and encrypted command traffic with a plaintext fallback mode. It enabled arbitrary shell command execution through child process invocation and included update mechanisms that could pull new payloads from operator-supplied content identifiers or polling channels. Persistence methods covered major desktop/server platforms, including shell startup modification on macOS, autorun registration on Windows, and user-level systemd service creation on Linux. The recovered codebase also contained additional capabilities for credential harvesting, propagation, evasion, mutation, AI-tool poisoning, and deadman-switch behavior, although those features were disabled in the analyzed build. Because attribution in this case is explicitly inconclusive, M-RED-TEAM should be treated as a payload or framework designation rather than a confidently attributed threat actor identity. Available evidence does not establish whether the operators behind the AsyncAPI compromise were the original developers or habitual users of M-RED-TEAM, or whether the branding reflected code reuse, imitation, or deliberate false-flagging.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.