Kothamine malware uses Tailscale’s tailcat to evade network detection 

Imported from official source

Cybersecurity Classified by Officially

We discovered an undocumented remote-access Trojan (RAT) called Kothamine Agent. It supports more than 30 commands and it gives attackers control of an infected Windows computer: they can run commands, read and change files, and add new capabilities. Some versions can also steal browser data and record through the camera and microphone. 

We found Kothamine linked to malicious npm packages, which could put users and developers who install those packages at risk. In recent versions, the malware uses tailcat, an open-source tool from Tailscale, to receive commands over an encrypted connection. That makes its communications harder to inspect and gives defenders no conventional command-and-control (C2) domain to block.

Based on VirusTotal uploads and GitHub commits, Kothamine appears to have been in development or distribution since at least July. Earlier versions used the Tailscale VPN instead of tailcat. Depending on the build, the malware includes the networking tools or downloads them from sources including GitHub.

Before installing an unfamiliar npm package, check its repository, maintainers, dependencies, and recent releases. Search for reports of malicious activity, and favor packages with an established history and regular maintenance.

  • Check the name carefully. Make sure you aren’t downloading a fake package with a similar name. 
  • Check the developer or organization and make sure the publisher appears legitimate. Check, for example, if it has a website or a GitHub repository. 
  • Read some reviews, issues and reports. Search for the package name on Google and check for reports of detected potential malware. 
  • Look at how popular it is. A package with many downloads and users is generally easier to verify than a brand-new package with almost no history. 
  • Kothamine and the malicious npm packages

    This is an extract. The publication continues at the source.

    Read the original at the source: https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection

    Officially imported this from Malwarebytes’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    Malwarebytes — imported from official source
    Official source
    https://www.malwarebytes.com/blog/feed/index.xml RSS
    Imported
    September 25, 2026 16:00
    Versions
    1 recorded
    Identity
    https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscale...

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.