Security1 distinct publisher2 min readPublished
Kaspersky found two cross-platform JavaScript RATs, NodeRabbit and PollCat, reaching engineers in aviation and fintech through fake recruiters, from a group that until now shipped native C, C++ and Go.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The control failure worth studying is in the README. TaskFlow shipped as a software engineering assessment built with Express, React and Vite, and the instructions told the candidate to review the app and fix defects in the frontend while asserting that server.js was bug-free and should not be modified [9]. server.js was the only application source file the attackers had altered [9]. The same README set a three-hour time limit and forbade the use of AI assistants [10]. All three instructions pushed scrutiny away from the same file [20].
The chain under it is short. The first line of server.js imported a package named colorized_terminal, pinned to version 2.1.0 [12]. The attackers bundled that package directly into the archive's node_modules directory instead of publishing it [13]. On import, it silently launched node_modules/.cache/.320697f1/index.js as a detached background process [14].
Kaspersky's initial access section rests on two kinds of evidence. The archive, its MD5 and the S3 URL came from telemetry, as did the three infected hosts [8][3]. The recruiter detail, an actor posing as a talent acquisition specialist at a major technology company and pressuring the target to download and run the project immediately, comes from a publicly cited post rather than from Kaspersky's own data, and Kaspersky says that post matches the delivery chain it reconstructed [16][17].
There is a caveat on scope. The report is framed around aviation and fintech across the Middle East and Africa [7], while the three recovered variants sat on hosts in Afghanistan, Egypt and Ethiopia [3], so one of the three is outside the stated region [22]. Read the region as where the telemetry landed, not as the boundary of the campaign.
For hunting, the surface is narrow. Kaspersky saw two trojanized package names across the three variants, colorized_terminal and pretty-log, both pinned to 2.1.0 [4], and detects the family as Trojan.JS.MirageKitten.* [18]. Kaspersky says PollCat, which has a substantially different structure and arrived through a separate coding challenge lure, will be analysed later in the same research [19]. Both sets of artifacts live where the interview did: a project directory on an engineer's workstation, with the interpreter already installed because the task required it.
Ranked by verification strength, evidence, and original report placement.
Kaspersky, while monitoring Mirage Kitten activity, uncovered a previously undocumented malware family it dubbed NodeRabbit, a cross-platform remote access trojan built with Node.js that targets Windows, Linux and macOS.
During the same investigation Kaspersky discovered a second previously undocumented family, PollCat, also a cross-platform RAT but written in obfuscated JavaScript and also distributed through trojanized coding challenge archives.
Kaspersky identified the first NodeRabbit sample on a system in Afghanistan, and threat hunting revealed two additional, more advanced variants, one on a system in Egypt and another on a system in Ethiopia.
Retrospective hunting identified three NodeRabbit variants with a shared code lineage, each recovered from a system in a different country, delivered through similarly themed coding challenges using two trojanized packages, colorized_terminal and pretty-log, both pinned to version 2.1.0.
Operators deliver NodeRabbit through spear-phishing messages on LinkedIn and other job search platforms that contain trojanized coding challenge archives, with the infection chain beginning with fake recruiter accounts contacting prospective targets.
Mirage Kitten has historically relied on native malware written in languages such as C, C++ and Go, often deployed through DLL search-order hijacking; Kaspersky calls NodeRabbit and PollCat the first publicly documented use of Node.js- and JavaScript-based malware by this APT group.
Distinct publishers with included, body-backed reporting in this cluster.
Follow any of these and your For You feed starts watching them — no settings page required.
invest
Singapore's exchange raids stop looking like incident response2 distinct publishers
build
A key in the app binary is a bucket handover; presigned uploads also drop the proxy data bill1 distinct publisher
security
Two Artifactory flaws poisoned metadata, not artifacts, and that was enough to break a shared cache1 distinct publisher
build
One outside engineer with one day turns a handover claim into a diff1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Sharp artifacts, one witness
The forensic layer is unusually specific for a first disclosure: an archive MD5, a full S3 URL, two package names pinned to the same version, an exact implant path, a loopback port used as a mutex. Anyone with a copy of that zip can check it. The framing layer is thinner — the aviation and fintech targeting lives in the title and nowhere in the narrative, and the outside corroboration Kaspersky invokes is an unnamed public post. Strong where it names bytes, unverified where it names victims.
Three machines on record
Counted honestly, the campaign's disclosed footprint is three hosts in three countries, all inside one vendor's visibility, plus a lure archive on a bucket and a detection signature now shipping. That is early-stage tooling caught in the act rather than a wave. The technique — bundle the poisoned dependency, skip the registry — is the part that travels; there is no evidence yet that anyone but this crew is running it.
Headline reaches further than the telemetry
The title promises aviation and FinTech across the Middle East and Africa; the body delivers three developer workstations, the anchor one of them in Afghanistan, and never names a sector or an employer. That is the gap, and it is a framing gap rather than a fabrication — the technical core is if anything undersold, since the bundled-dependency trick defeats the scanning most teams rely on and gets a single sentence. The AI-assistant counterfactual is the other stretch: plausible, untested, and conveniently flattering to a tooling category.
Finder, namer and seller in one
Kaspersky discovered the activity, chose both malware names, and closes the summary with the signature its products match. The AI-review aside points the same way — it turns a lure design detail into an argument for automated code review. None of that makes the artifacts wrong; a vendor's telemetry is the only place findings like this can come from first. It does mean the scope language and the 'first publicly documented' framing deserve reading as marketing-adjacent until someone without a product confirms them.
Credible primary account, nothing to cross-check
Confidence sits in the middle for a structural reason, not a quality one: one publisher, and it is the investigating vendor. The concrete indicators would be hard to invent and easy to falsify, which pulls upward. The single-witness posture, the withheld PollCat analysis and the uncited corroborating post pull the other way. A second vendor bulletin or a CERT advisory reusing these indicators would move this materially.