Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Linux Malware Poses Threat to Software Developers

New Linux Malware Poses Threat to Software Developers

Posted on May 6, 2026 By CWS

A novel cybersecurity threat has been identified within the Linux ecosystem, posing significant risks to software developers and potentially endangering entire supply chains. This threat, known as Quasar Linux or QLNX, is a remote access trojan with capabilities specifically designed to operate stealthily within Linux environments, using sophisticated credential theft techniques.

Technical Details of QLNX

QLNX is engineered to execute entirely in memory, effectively avoiding detection by traditional disk-based security measures. It copies itself into a RAM-backed file and erases its binary from the disk, leaving no footprint. Additionally, QLNX uses deceptive process names that mimic legitimate Linux kernel threads, such as [kworker/0:0], making it difficult for even vigilant administrators to recognize unusual activity.

The trojan’s internal structure, uncovered by Trend Micro’s AI-driven threat hunting platform, includes embedded source code for both a rootkit and a PAM backdoor. These components are compiled at runtime using the system’s GCC compiler and loaded via /etc/ld.so.preload to monitor and intercept system-wide activities.

Scope and Impact on Software Development

QLNX’s ability to harvest credentials on a large scale is particularly concerning. It targets SSH private keys, browser login data, and cloud configuration files for platforms such as AWS and Kubernetes. Furthermore, it seeks out Docker credentials, Git tokens, and other essential authentication data, transmitting this information to a command-and-control server through encrypted channels.

The malware’s peer-to-peer mesh networking capabilities enable it to relay commands between infected hosts, complicating efforts to eliminate it from affected systems. Developers are urged to monitor for process names that mimic kernel threads, scrutinize /etc/ld.so.preload for anomalies, and audit developer workstations for suspicious shared library files.

Supply Chain Risks and Mitigation Strategies

The true danger of QLNX extends beyond compromising individual machines. Developers are prime targets due to their access to publishing pipelines for widely used software packages. By capturing NPM and PyPI tokens, QLNX’s operators can inject malicious code into trusted registries, potentially affecting thousands of users without immediate detection.

Supply chain attacks through platforms like PyPI and npm have risen as a preferred method for cybercriminals. A single compromised developer account can lead to the trojanization of legitimate packages, insertion of backdoors into build artifacts, or unauthorized access to cloud environments where production systems reside. The initial compromise can propagate across servers using SSH keys before being detected.

Conclusion: A Call to Action

QLNX employs advanced techniques to remain undetected and persist through system reboots. Its use of systemd services, crontab entries, init.d scripts, and modifications to .bashrc files ensures it can survive attempts to remove it. Organizations managing Linux environments should prioritize immediate reviews of endpoint visibility and bolster their credential storage security to mitigate this urgent threat.

Cyber Security News Tags:cloud security, credential theft, Cybersecurity, Linux, Malware, QLNX, remote access trojan, software developers, supply chain, threat detection

Post navigation

Previous Post: CloudZ RAT Exploits Microsoft Feature to Steal OTPs
Next Post: Russian Ransomware Operator Sentenced to 102 Months

Related Posts

Hackers Use Fake Job Portals to Spread Malware Hackers Use Fake Job Portals to Spread Malware Cyber Security News
Microsoft Enhances Teams for iOS and Android Microsoft Enhances Teams for iOS and Android Cyber Security News
Palo Alto Networks Acknowledges SquareX Research on Limitations of SWGs Against Last Mile Reassembly Attacks Palo Alto Networks Acknowledges SquareX Research on Limitations of SWGs Against Last Mile Reassembly Attacks Cyber Security News
Cisco ISE Flaws Enable Remote Code Execution Risk Cisco ISE Flaws Enable Remote Code Execution Risk Cyber Security News
WhatsApp’s New Username Feature Enhances Privacy WhatsApp’s New Username Feature Enhances Privacy Cyber Security News
SpankRAT Threatens Windows Security with Stealth Techniques SpankRAT Threatens Windows Security with Stealth Techniques Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GentleKiller Exploits Drivers to Bypass 400+ Security Tools
  • CyberSentinel AI Revolutionizes Security with 33 Tools
  • Macron Advocates Global AI Regulation at G7 Summit
  • Gravity SMTP Plugin Vulnerability Exposes API Keys
  • AutoJack Exploit Risks AI Agents with Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GentleKiller Exploits Drivers to Bypass 400+ Security Tools
  • CyberSentinel AI Revolutionizes Security with 33 Tools
  • Macron Advocates Global AI Regulation at G7 Summit
  • Gravity SMTP Plugin Vulnerability Exposes API Keys
  • AutoJack Exploit Risks AI Agents with Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark