Quasar Linux (QLNX) Malware Targets Software Developers for Supply Chain Attacks

Quasar Linux (QLNX) Malware Targets Software Developers for Supply Chain Attacks

First seen 5 May 2026, 22:25 UTC TrendmicroBleepingcomputerCsoonlineSocprimeHeise.De+4 86% similarity 67.5

Article Content

Browse articles
ThreatCluster

Quasar Linux (QLNX) is a newly discovered Linux remote access trojan (RAT) targeting software developers. It features rootkit capabilities, credential harvesting, and stealth mechanisms, making it suitable for supply chain attacks. The malware operates in development environments such as npm, PyPI, GitHub, AWS, Docker, and Kubernetes. Researchers from Trend Micro found that QLNX can dynamically compile malicious modules on infected systems and employs multiple persistence techniques to maintain access. It has a low detection rate, with only four security solutions currently flagging it as malicious. The malware's design allows attackers to inject trojanized packages into legitimate repositories, potentially affecting a wide range of users. Trend Micro has provided indicators of compromise (IoCs) to assist in detection and mitigation efforts. The specific volume of QLNX deployments and any attributed attacks remain unclear.

Key Points: • Quasar Linux (QLNX) is a sophisticated Linux RAT designed for stealth and persistence. • The malware targets developer environments and can facilitate supply chain attacks by trojanizing packages. • Only four security solutions currently detect QLNX, highlighting its low detection rate.

ThreatCluster AI

Timeline

2026-05-04
Trend Micro discovers Quasar Linux (QLNX)
Researchers identified QLNX as a previously undocumented Linux RAT with advanced capabilities targeting software developers.
Trendmicro
2026-05-05
BleepingComputer reports on QLNX
BleepingComputer published findings on QLNX, detailing its stealth mechanisms and potential for supply chain attacks.
Bleepingcomputer

Community

Browse all →