Kothamine malware uses Tailscale’s tailcat to evade network detection
Cybersecurity Classified by Officially
We discovered an undocumented remote-access Trojan (RAT) called Kothamine Agent. It supports more than 30 commands and it gives attackers control of an infected Windows computer: they can run commands, read and change files, and add new capabilities. Some versions can also steal browser data and record through the camera and microphone.
We found Kothamine linked to malicious npm packages, which could put users and developers who install those packages at risk. In recent versions, the malware uses tailcat, an open-source tool from Tailscale, to receive commands over an encrypted connection. That makes its communications harder to inspect and gives defenders no conventional command-and-control (C2) domain to block.
Based on VirusTotal uploads and GitHub commits, Kothamine appears to have been in development or distribution since at least July. Earlier versions used the Tailscale VPN instead of tailcat. Depending on the build, the malware includes the networking tools or downloads them from sources including GitHub.
Before installing an unfamiliar npm package, check its repository, maintainers, dependencies, and recent releases. Search for reports of malicious activity, and favor packages with an established history and regular maintenance.
Kothamine and the malicious npm packages
This is an extract. The publication continues at the source.
Read the original at the source: https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection
Officially imported this from Malwarebytes’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Malwarebytes — imported from official source
- Official source
- https://www.malwarebytes.com/blog/feed/index.xml RSS
- Imported
- September 25, 2026 16:00
- Versions
- 1 recorded
- Identity
https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscale...