Kothamine Malware Uses Tailscale's Tailcat to Evade Network Detection
Kothamine Malware Uses Tailscale’s Tailcat to Evade Network Detection 🚨
We discovered an undocumented remote-access Trojan (RAT) called Kothamine Agent. It supports more than 30 commands and gives attackers control of an infected Windows computer: they can run commands, read and change files, and add new capabilities. Some versions can also steal browser data and record through the camera and microphone.
We found Kothamine linked to malicious npm packages, which could put users and developers who install those packages at risk. In recent versions, the malware uses tailcat, an open-source tool from Tailscale, to receive commands over an encrypted connection. This makes its communications harder to inspect and gives defenders no conventional command-and-control (C2) domain to block.
Based on VirusTotal uploads and GitHub commits, Kothamine appears to have been in development or distribution since at least July. Earlier versions used the Tailscale VPN instead of tailcat. Depending on the build, the malware includes the networking tools or downloads them from sources including GitHub.
Precautions to Take ⚠️
Before installing an unfamiliar npm package, check its repository, maintainers, dependencies, and recent releases. Search for reports of malicious activity, and favor packages with an established history and regular maintenance. Users should also check the name carefully to ensure they aren’t downloading a fake package with a similar name. Verify the developer or organization to ensure the publisher appears legitimate. Check, for example, if it has a website or a GitHub repository. Read some reviews, issues, and repo.