Threat intel
Kothamine RAT hides its commands inside Tailscale's tailcat
A Windows RAT spread through a malicious npm package gets its orders over tailcat, so there is no C2 domain to block. How to find it on hosts and on the wire.
Malwarebytes has documented Kothamine, a Windows remote access trojan (RAT) that it says has been in development since at least July 2026. It reached victims through a malicious npm package, dotnet-runtime-base, and gives its operator more than 30 commands: shell access, file and process control, screenshots, camera and microphone recording, and in some builds, theft of browser cookies and gaming accounts.
The part that matters for defenders is how it takes orders. Recent builds carry tailcat, an open-source tool Tailscale released in late August, and use it to pull commands over an encrypted WireGuard tunnel. There is no attacker domain in the traffic and no Tailscale account to report, so a domain blocklist or a threat intelligence feed of C2 hosts will not catch it. Developers and build servers that ran npm install on Windows are the ones to check first.
How it works
The npm package does the delivery. According to the malicious package advisory (GHSA-9gr8-wg29-9wvv, filed by Amazon Inspector on July 13), versions 1.0.4 and 1.0.5 run install.js as a postinstall script. On Windows it writes a PowerShell script to %TEMP%, downloads an executable from an unrelated GitHub account with WebClient.DownloadFile, and runs it hidden with the execution policy bypassed. The script skips execution when NODE_ENV is set to development, so a developer testing locally may see nothing while a CI runner or a fresh machine gets infected.
Malwarebytes tied the GitHub account (cphc811-ui) to npm-sc-legit.exe, a compiled Kothamine build. The malware comes in two parts written in C/C++: an injector and a DLL agent. The injector copies itself to %APPDATA%\MicrosoftEdgeUpdateCore.exe, registers a scheduled task named MicrosoftEdgeUpdateTask through a script called up.ps1, tries to add Microsoft Defender exclusions with Add-MpPreference -ExclusionPath and -ExclusionProcess, and loads the agent into explorer.exe with the classic VirtualAllocEx, WriteProcessMemory and CreateRemoteThread sequence. Some builds also bypass User Account Control (UAC) by abusing fodhelper.exe to run an elevated PowerShell script.
The agent is extensible. The load_feature command takes a base64-encoded DLL, and any plugin that exports a GetFeatureApi function becomes a new capability. Messages are encrypted with AES-GCM using a key hardcoded in the binary.
Why tailcat hides the C2
Tailscale describes tailcat as netcat over its data plane without its control plane. Two machines connect using Tailscale's WireGuard encryption, NAT traversal and DERP (Designated Encrypted Relay for Packets) servers, which relay traffic when a direct UDP path cannot be set up. There is no account, no login and no device registration. The server hands out an address starting with tc that encodes its public keys and a pre-shared key, and anyone holding that string can connect.
Kothamine extracts tailcat to %APPDATA%\TailscalePortable\tailcat.exe and starts it with forward tc... 18080:4444. That opens a local listener on 127.0.0.1:18080 which tunnels to port 4444 on the operator's machine. The agent then talks only to loopback. From the network's point of view, the host is making ordinary WireGuard or HTTPS connections to shared, Tailscale-run relays.
Earlier builds used the full Tailscale client instead. They ran tailscaled.exe hidden and joined the attacker's network with tailscale.exe up --unattended=true and a tskey-auth- key. That approach leaves an account and an auth key that Tailscale can revoke. Tailcat has neither.
What attackers are doing
No victim count or attribution has been published. What is known comes from the npm advisory and the Malwarebytes analysis of September 25:
- The two malicious npm versions were flagged in a public advisory on July 13. Malwarebytes found that two other packages from the same publisher had already been removed.
- The package documentation included build instructions for
kothamine-stub-cppand a guide to loading .NET assemblies, which Malwarebytes did not see in the samples it analysed. - Stealer builds grab cookies from several browsers, the clipboard, and Steam, Minecraft and Discord data, which suggests the operators expect developers and gamers on personal or lightly managed Windows machines.
What to do
Start with the dependency tree, then the hosts, then the network.
- Search every lockfile and build log for
dotnet-runtime-base, or runnpm ls dotnet-runtime-basein each project. Check CI runners and developer laptops as well as the repositories. Any Windows machine that installed version 1.0.4 or 1.0.5 should be treated as compromised. - On Windows hosts, look for
%APPDATA%\MicrosoftEdgeUpdateCore.exeand.dll,%APPDATA%\TailscalePortable\tailcat.exe, and%TEMP%\up.ps1orelevated.ps1. RunGet-ScheduledTask -TaskName MicrosoftEdgeUpdateTaskand review Defender exclusions withGet-MpPreference | Select-Object ExclusionPath, ExclusionProcess. The published SHA-256 hashes areec4219a7ecf132c29080fbb20e4ab410c57faa85aeed7acade1eb15d905a6ee0(injector) and74eca3973ad72a6ddc9397aff8250d9ee287211fc9a055d5ee290d01cf76a70c(agent). - Hashes are trivial to change between builds, so also query your EDR (endpoint detection and response) tool for any process whose command line contains
forward tc, anytailcat.exeortailscaled.exeoutside an approved install path,explorer.execonnecting to a loopback port such as 18080, andfodhelper.exespawning PowerShell. - Alert on overlay traffic from hosts that should not have it. Tailscale's own firewall guidance lists the signals: STUN on UDP 3478, direct WireGuard on UDP 41641 by default for the Tailscale client, and HTTPS on TCP 443 to the coordination server and DERP relays. Tailcat's default relay list comes from
https://tailcat.dev/derpmap.json; at the time of writing it names four relays,tc301a.ipn.devtotc304a.ipn.dev. A DNS lookup fortailcat.devoripn.devfrom a workstation that has no reason to run tailcat is worth an alert. An operator can run their own DERP server, so treat these names as one signal among several. - Block outbound UDP from workstations and build agents except to your DNS resolvers and approved VPN endpoints, so tunnels fall back to DERP over TCP 443, where proxy logs see them. Use
npm ci --ignore-scriptsin CI, orignore-scripts=truein.npmrc, and allow scripts only for packages that need them. AppLocker or App Control for Business rules that stop executables running from%APPDATA%would block both the injector and the tailcat copy.
If a machine was hit, rebuild it. The npm advisory warns that removing the package does not guarantee the malware is gone. From a clean device, rotate every secret the machine held: npm and GitHub tokens, cloud keys, SSH keys, and browser sessions, since stealer builds take cookies. Sign out of Discord and Steam sessions too.
Allow-list the tunnels, then watch for the rest
Attackers borrow legitimate remote access and tunnelling tools because many networks already let them through, and Kothamine does the same with an overlay network. The control that holds up is an inventory: decide which hosts may run Tailscale, tailcat, or similar tools, and alert on the process and the traffic everywhere else.
We check egress rules, application control and endpoint telemetry for this kind of gap in our safeguarding and hardening work, and hunt for it in security operations. If you think a developer machine or build agent ran this package, open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: Malwarebytes, OSV MAL-2026-10217 (GHSA-9gr8-wg29-9wvv), OffSeq Threat Radar, Mallory, Hendry Adrian weekly recap, Tailscale tailcat announcement, tailcat on GitHub, Tailscale firewall ports.