Overview
- Kaspersky researchers traced suspicious activity to S3‑hosted archives sent as LinkedIn take‑home coding tests and publicly reported two new Node.js implants named NodeRabbit and PollCat.
- The delivery used realistic recruiter personas, a README that imposed a short time limit and forbade AI tools to stop automated code review, and fully legitimate cloud hosting to reduce detection cues.
- NodeRabbit is a cross‑platform Node.js implant that runs on Windows, macOS and Linux, starts a background process, talks to Azure command servers using AES‑256‑GCM, and includes sandbox checks and variants that add persistence via a fake VS Code extension and Git hook injection.
- PollCat is packaged as a React coding challenge that shows a countdown and begins communicating with its command server as soon as the app loads rather than after a candidate enters an access code.
- Kaspersky linked both families to the Mirage Kitten APT with high confidence based on near‑identical network behavior including extracting session tokens from HTTP 400 responses, and identified victims in fintech and aviation in Egypt, Ethiopia and Afghanistan, which raises fresh risk for developer hiring workflows and open source supply chains.