Skills
QLNX: New Stealthy Linux RAT Targets Developer Workstations — Harvests SSH Keys, Git/npm/PyPI Tokens, Cloud Configs for Supply Chain Attacks, Detected by Only 4 Products
Researchers disclosed Quasar Linux (QLNX), a previously undocumented in-memory RAT targeting developer and DevOps workstations. It runs a multi-stage credential harvest sweeping SSH private keys, browser login DBs, AWS/K8s configs, Docker credentials, Git tokens, npm tokens, PyPI API keys, and .env files. It deletes its binary, wipes logs, spoofs process names, and clears forensic environment variables. Only 4 security products detect it. A single compromised maintainer account enables trojanizing legitimate packages, injecting build backdoors, or pivoting to cloud production infrastructure.
↳ Follow the thread