logo

QLNX Targets Developers With Credential Theft Designed for Supply Chain Compromise

ID: d0a4e6b9-6d90-5fb8-8cbe-5be600ec4163

STIX ID: report--d0a4e6b9-6d90-5fb8-8cbe-5be600ec4163

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-05-06

Date Updated: 2026-05-08

Author: Tushar Subhra Dutta

...
...

Quasar Linux (QLNX) is a sophisticated Linux remote-access trojan that operates in memory, compiles and injects a rootkit and PAM backdoor at runtime, harvests a wide range of developer credentials (SSH keys, cloud configs, NPM/PyPI tokens, etc.), uses eBPF-level hiding and P2P relaying to resist detection and removal, and includes extensive persistence and log-wiping capabilities; the report includes multiple file and hash IoCs and recommended detection steps for developer and cloud environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.