New stealthy Quasar Linux malware targets software developers
2026-05-06T01:23:31Z•c27a1b1107f37e018dd531568a32af5282f49781a864992f726b3cfde2446e68
amazon-ses-abusebackdoorcloudzcredential-theftdata-breachinstructurekochavalinux-malwarelocation-privacymobile-malwareotp-stealingphishingpyPI-malicious-packagequasar-linuxregulatoryrootkitsms-stealingsoftware-supply-chainsupply-chaintrellix-breachvimeovulnerabilityweaverweaver-e-cologyweaver-e-cology-exploit
What happened
Multiple high-impact security incidents and campaigns were reported: a previously undocumented Linux implant called Quasar Linux (QLNX) is targeting developers with rootkit, backdoor, and credential-stealing capabilities; DAEMON Tools installers were trojanized in a supply‑chain attack since April 8 delivering a backdoor to thousands of systems; a malicious PyTorch Lightning package on PyPI delivered a credential stealer; CloudZ RAT added a Pheno plugin that hijacks Microsoft Phone Link to steal SMS/OTPs; and ScarCruft (APT37) pushed BirdCall Android malware via a game-platform supply chain. A
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- c27a1b1107f37e018dd531568a32af5282f49781a864992f726b3cfde2446e68
- Enrichment time
- 2026-05-06T01:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.