Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities
Trend Micro researchers disclosed Quasar Linux (QLNX), a previously undocumented, full-featured Linux RAT targeting developer workstations and supply-chain infrastructure. The malware combines fileless execution, eBPF rootkit capabilities, PAM credential interception, SSH key harvesting, and P2P mesh networking to maintain persistent, stealthy access while exfiltrating development credentials (NPM, PyPI, AWS, Kubernetes, Docker, Git tokens). QLNX's primary attack surface is package maintainers and DevOps engineers, enabling supply-chain poisoning of open-source ecosystems.