Sliver, an open-source command-and-control (C2) framework, is deployed as the final payload on Linux systems in the malicious npm campaign. The Linux sample is an UPX-packed ELF binary that downloads auxiliary payloads from a Cloudflare Worker URL, ultimately leading to Sliver deployment.