Trojanized npm packages launch RedC2 4.0 on Linux at import time, giving operators shell access, credential theft, and ...