logo

New Quasar Linux (QLNX) RAT Hijacks Cloud Keys and NPM Tokens

ID: bd835fbd-f5c4-5720-959d-6a3fb044e78a

STIX ID: report--bd835fbd-f5c4-5720-959d-6a3fb044e78a

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Ddos

...
...

Trend Micro disclosed QLNX (Quasar Linux), a stealthy Linux RAT that targets developer workstations and the software supply chain by harvesting high-value credentials (npm/PyPI tokens, cloud keys, kubeconfigs, Git/GitHub/Vault tokens), using fileless execution (memfd_create), process-name spoofing, a compiled PAM backdoor deployed via /etc/ld.so.preload, a two-tier rootkit (LD_PRELOAD and eBPF), and a P2P mesh for resilient C2 — enabling trojanized packages, backdoored build artifacts, and cloud pivoting from a single compromised developer host.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.