New stealthy Quasar Linux malware targets software developers

2026-05-06T01:23:31Zc27a1b1107f37e018dd531568a32af5282f49781a864992f726b3cfde2446e68
amazon-ses-abusebackdoorcloudzcredential-theftdata-breachinstructurekochavalinux-malwarelocation-privacymobile-malwareotp-stealingphishingpyPI-malicious-packagequasar-linuxregulatoryrootkitsms-stealingsoftware-supply-chainsupply-chaintrellix-breachvimeovulnerabilityweaverweaver-e-cologyweaver-e-cology-exploit

What happened

Multiple high-impact security incidents and campaigns were reported: a previously undocumented Linux implant called Quasar Linux (QLNX) is targeting developers with rootkit, backdoor, and credential-stealing capabilities; DAEMON Tools installers were trojanized in a supply‑chain attack since April 8 delivering a backdoor to thousands of systems; a malicious PyTorch Lightning package on PyPI delivered a credential stealer; CloudZ RAT added a Pheno plugin that hijacks Microsoft Phone Link to steal SMS/OTPs; and ScarCruft (APT37) pushed BirdCall Android malware via a game-platform supply chain. A

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
c27a1b1107f37e018dd531568a32af5282f49781a864992f726b3cfde2446e68
Enrichment time
2026-05-06T01:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.