logo

Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise

ID: c8affaa3-1106-58fe-9ff2-6a1884e3a418

STIX ID: report--c8affaa3-1106-58fe-9ff2-6a1884e3a418

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-05-08

Date Updated: 2026-05-11

Author: [email protected] (The Hacker News)

...
...

**Quasar Linux RAT (QLNX)** is a sophisticated Linux implant observed targeting developers and DevOps credentials across the software supply chain; it runs filelessly, hides via LD_PRELOAD and an eBPF kernel component, installs multiple persistence mechanisms (systemd, crontab, .bashrc, etc.), hooks PAM to capture plaintext credentials and SSH session data, supports broad post-compromise actions (keylogging, screenshots, file manipulation, SOCKS/TCP tunneling, BOF execution, P2P mesh), and harvests high-value secrets (.npmrc, .pypirc, .aws/credentials, .kube/config, .docker/config.json, .vault-token, Terraform creds, GitHub tokens, .env files) that could allow attackers to poison package registries or pivot through CI/CD pipelines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.