Researchers identified Kothamine Agent, an undocumented C/C++ Windows remote-access Trojan linked to malicious npm packages including dotnet-runtime-base. The RAT persists through a scheduled task, injects its agent DLL into explorer.exe, attempts to add Microsoft Defender exclusions, and gives operators more than 30 commands for system, process, file, and shell control as well as loading of additional DLL plugins.
Recent Kothamine variants use Tailscale's tailcat utility to create encrypted command-and-control channels without a conventional C2 domain, replacing earlier use of the Tailscale VPN and making network detection more difficult. Some builds also incorporate UAC-bypass and surveillance or theft functions, including browser-cookie and clipboard theft, screenshots, camera and microphone capture, and collection of Steam, Minecraft, and Discord-related data.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
MAL-2026-10217/GHSA-9gr8-wg29-9wvv disclosed that dotnet-runtime-base versions 1.0.4 and 1.0.5 use a Windows-only postinstall script to download and covertly execute npm-sc-legit.exe through PowerShell. The advisory rated the malicious package CVSS 10.0 and advised affected users to treat systems as fully compromised and rotate secrets from a trusted device.
Recent Kothamine variants extract Tailscale's tailcat utility and use it to forward a local listener to an operator-controlled port, avoiding a conventional C2 domain and Tailscale account or device registration. The malware communicates with the local listener over sockets and encrypts C2 messages with AES-GCM.
The malicious npm package dotnet-runtime-base downloaded npm-sc-legit.exe from a GitHub repository; the executable was a compiled Kothamine variant with data-stealing commands. Package authors also exposed build instructions for kothamine-stub-cpp in one malicious package.
Earlier Kothamine builds used the Tailscale VPN for command-and-control functionality, in some cases downloading Tailscale components from official or GitHub-hosted sources.
VirusTotal uploads and GitHub commits indicate that the undocumented C/C++ Kothamine Windows remote-access Trojan had been under development or distribution since at least July.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalwarebytes.com
Open sourcemondoo.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.