NodeRabbit is a cross-platform Node.js remote-access trojan (RAT) attributed with high confidence to the Iran-linked cyberespionage actor Mirage Kitten, also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore. It targets Windows, Linux, and macOS developer workstations, particularly personnel associated with fintech, aviation, and aerospace organizations in the Middle East and Africa. Confirmed infections have been identified in Afghanistan, Egypt, and Ethiopia.
Mirage Kitten distributes NodeRabbit through recruitment-themed spearphishing, using impersonated recruiters on LinkedIn and other employment platforms to send trojanized programming assessments. The assessments package apparently legitimate developer projects with locally bundled malicious Node.js dependencies. Executing the project starts NodeRabbit as a detached background process.
NodeRabbit gathers host, network, process, directory, mounted-volume, and development-project information; executes shell commands and attacker-supplied Node.js code; and performs file creation, modification, deletion, and other filesystem operations. Later variants can discover Outlook account information, terminate processes, alter beacon configuration, and replace active command-and-control servers. Command-and-control traffic is protected with AES-256-GCM, and some variants support enterprise proxy discovery and authenticated proxy tunneling.
NodeRabbit includes anti-analysis checks for sandbox-like system characteristics, suspicious host or user names, and analysis tooling. Variants can terminate without contacting their command-and-control infrastructure when analysis is suspected. Persistence mechanisms vary by platform and version, including Windows startup or scheduled-execution mechanisms, Linux cron, and macOS launch agents. A more advanced variant adds developer-workflow persistence by installing a counterfeit Visual Studio Code extension that launches the RAT when the editor opens and by inserting launchers into Git hooks so normal repository operations can restart the malware. These capabilities provide the operator with durable remote access and create material risk to source code, internal repositories, corporate services, and locally accessible email data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mirage Kitten delivers NodeRabbit through fake developer coding challenges; a bundled malicious Node.js package launches it from a hidden cache path.
Mirage Kitten delivers NodeRabbit through fake developer coding challenges; a bundled malicious Node.js package launches it from a hidden cache path.
NodeRabbit is a cross-platform RAT developed using Node.js... More advanced variants introduce anti-analysis checks, corporate proxy support, expanded C2 capabilities, Outlook account discovery, and persistence through malicious Visual Studio Code extensions and Git hooks.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Its first line instead imported colorized_terminal version 2.1.0, a malicious package bundled inside node_modules rather than obtained from npm; loading it launched NodeRabbit from a hidden cache path.
“The first line of server.js imported a malicious npm package named colorized_terminal... attackers bundled it directly inside the archive's node_modules directory.”
NodeRabbit gathers host and network details, lists processes, runs shell commands... PollCat provides ... shell access, and arbitrary JavaScript execution.
Les chemins incluent ~/Library/LaunchAgents/com.microsoft.edgeupdate.plist, com.intel.dsa.helper et com.harsh.requireobject.plist.
Les chemins incluent ~/Library/LaunchAgents/com.microsoft.edgeupdate.plist, com.intel.dsa.helper et com.harsh.requireobject.plist.
“NodeRabbit can create an extension masquerading as GitHub Copilot Helper,” and actors “incorporated a targeted organization's name into Azure subdomains.”
La persistance est masquée en Microsoft Edge Update ou Intel DSA; une fausse extension VS Code est nommée GitHub Copilot Helper.
T1016 — System Network Configuration Discovery (Discovery).
NodeRabbit gathers host and network details... PollCat provides file transfers, system inventory...
Its third variant expands to 23 commands and searches for Outlook addresses, mounted drives, development projects, and Git repositories.
“New functionality includes... Outlook account address discovery from OST and PST artifacts.”
Newer versions check for analysis environments... PollCat ... [checks] for traces of security products.
“[NodeRabbit] communicates with Azure-hosted C2 infrastructure using encrypted API requests.”
La variante Égypte prend en charge les proxys NTLM/Negotiate via curl.exe; cette délégation proxy est aussi citée comme similarité avec Retrograde/MiniFast.
“The malware supports HTTP CONNECT tunneling and can attempt Basic, NTLM, or Negotiate proxy authentication.”
[The] coding assessment [is] hosted on a completely legitimate-looking Amazon S3 link.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cross-platform remote-access trojan for Windows, Linux, and macOS. It inventories hosts and networks, enumerates processes, executes shell commands, manipulates files, evades analysis, handles enterprise proxies, rotates C2 servers, and searches for Outlook addresses, mounted drives, development projects, and Git repositories. It can persist or relaunch through a malicious VS Code extension and Git post-merge/post-checkout hooks.
A Node.js/JavaScript cross-platform remote-access trojan targeting developer workstations. It supports encrypted Azure-hosted C2, host and network reconnaissance, arbitrary shell and Node.js command execution, file operations, process enumeration, and persistence on Windows, Linux, and macOS. Advanced variants evade analysis environments, authenticate through enterprise proxies, enumerate Outlook accounts, alter C2 servers, and persist through malicious Visual Studio Code extensions, Windows Run keys, and Git post-merge/post-checkout hooks.
A cross-platform Node.js implant delivered in trojanized coding challenges. It establishes a background process and encrypted command-and-control communications, performs sandbox/analysis-environment checks, and later variants add expanded command support, malicious VS Code-extension deployment, and Git-hook persistence.
A cross-platform Node.js/JavaScript remote-access trojan used by Nimbus Manticore. It profiles hosts, processes, directories, files, network adapters and configuration; executes arbitrary shell commands; transfers and deletes files; and can execute temporary Base64-encoded Node.js scripts. It persists through Windows Run keys, Linux cron, or macOS launch agents; newer variants add WSL-aware persistence, Outlook artifact harvesting, Git repository hook persistence, and attempted fake VS Code extension installation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.