Malware · 144 giorni fa
Una workstation di sviluppo compromessa non è il punto di arrivo qui. QLNX è costruito per vivere a livello kernel, rubare credenziali di pubblicazione e cloud, e poi consentire agli attaccanti di continuare a usare account legittimi dei maintainer per avvelenare pacchetti o spostarsi nell'infrastruttura molto tempo dopo che l'host è stato ripulito.
3 fonti che coprono questa storia
Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise
Quasar Linux RAT (QLNX) harvests DevOps credentials to enable software supply chain attacks with fileless execution and dual rootkit stealth.
Sophisticated Quasar Linux RAT Targets Software Developers
The persistent, evasive implant provides remote access, surveillance, and credential exfiltration capabilities.
New stealthy Quasar Linux malware targets software developers
A previously undocumented Linux implant named Quasar Linux (QLNX) is targeting developers' systems with a mix of rootkit, backdoor, and credential-stealing capabilities.
Part of the PlainSec briefing for 2026-05-09