Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise
ID: c8affaa3-1106-58fe-9ff2-6a1884e3a418
STIX ID: report--c8affaa3-1106-58fe-9ff2-6a1884e3a418
Feed Name: The Hacker News
**Quasar Linux RAT (QLNX)** is a sophisticated Linux implant observed targeting developers and DevOps credentials across the software supply chain; it runs filelessly, hides via LD_PRELOAD and an eBPF kernel component, installs multiple persistence mechanisms (systemd, crontab, .bashrc, etc.), hooks PAM to capture plaintext credentials and SSH session data, supports broad post-compromise actions (keylogging, screenshots, file manipulation, SOCKS/TCP tunneling, BOF execution, P2P mesh), and harvests high-value secrets (.npmrc, .pypirc, .aws/credentials, .kube/config, .docker/config.json, .vault-token, Terraform creds, GitHub tokens, .env files) that could allow attackers to poison package registries or pivot through CI/CD pipelines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
