QLNX: New Remote Access Trojan targets Linux developers

FYI guys:

==> QLNX: New Remote Access Trojan targets Linux developers | heise online

Quasar Linux (QLNX) is not an operating system, but a supply chain attack tool that is difficult to detect and remove.
[…]
On infected systems, QLNX steals secrets for npm, PyPI, GitHub, Amazon Web Services (AWS), Docker, and Kubernetes. Information such as private SSH keys, browser logins, shell histories, clipboard content, and passwords stored unencrypted in the Linux PAM authentication process are also targeted by the data thieves.

Stay safe.

2 Likes