Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
NodeRabbit is a cross-platform remote access trojan (RAT) built with Node.js. It targets Windows, Linux, and macOS. Its operators deliver it through spear-phishing messages on LinkedIn and other job search platforms that contain trojanized coding challenge archives.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers bundled the trojanized colorized_terminal package directly in the challenge task archive's node_modules directory rather than publishing it to the npm registry.
On Linux, NodeRabbit creates an @reboot cron entry... PollCat appends both a daily 09AM cron line and an @reboot line.
Variant 2 creates a scheduled task named IntelDriverSupportUpdate, which runs daily at 10AM... PollCat creates a daily task named NetSync_<username>.
NodeRabbit proc:start executes an arbitrary shell command; PollCat RUN executes a shell command.
On Linux, NodeRabbit creates an @reboot cron entry... PollCat appends both a daily 09AM cron line and an @reboot line.
Variant 2 creates a scheduled task named IntelDriverSupportUpdate, which runs daily at 10AM... PollCat creates a daily task named NetSync_<username>.
It creates a fake extension displayed as GitHub Copilot Helper ... activation event on StartupFinished. The extension.js file attempts to start the installed payload.
NodeRabbit creates LaunchAgents with RunAtLoad and KeepAlive enabled. PollCat creates and loads ~/Library/LaunchAgents/com.harsh.requireobject.plist with RunAtLoad and a daily 09AM trigger.
Git-hook persistence appends a marked launcher to .git/hooks/post-merge and .git/hooks/post-checkout. A later Git operation must trigger one of those hooks.
On Linux, NodeRabbit creates an @reboot cron entry... PollCat appends both a daily 09AM cron line and an @reboot line.
Variant 2 creates a scheduled task named IntelDriverSupportUpdate, which runs daily at 10AM... PollCat creates a daily task named NetSync_<username>.
NodeRabbit creates LaunchAgents with RunAtLoad and KeepAlive enabled. PollCat creates and loads ~/Library/LaunchAgents/com.harsh.requireobject.plist with RunAtLoad and a daily 09AM trigger.
Git-hook persistence appends a marked launcher to .git/hooks/post-merge and .git/hooks/post-checkout. A later Git operation must trigger one of those hooks.
NodeRabbit's net:config enumerates adapters, MAC addresses, IP addresses, and DNS settings. Variant 2 re-runs proxy discovery after network-interface or IP-address changes.
NodeRabbit supports proc:list. PollCat supports TASKLIST and SYSTEM_CHECK, which collects the names of running processes.
NodeRabbit's sys:info returns hostname, domain user information, username, and process ID. PollCat's /gate/hello submits host, user, domain, OS information, and current privilege level.
NodeRabbit chooses from Azure-hosted C2 infrastructure addresses; on failure, it switches to the next C2 address. PollCat iterates over C2s until registration succeeds.
NodeRabbit communicates with command-and-control servers through API endpoints... PollCat registers through POST /beacon, polls GET /gate/fetch, and submits results through POST /gate/submit.
Variant 2 checks HTTP(S) proxy environment variables, Windows Internet Settings ... and tunnels its HTTPS C2 through HTTP CONNECT.
PollCat UPLOAD downloads a file from the C2 to the victim's machine; NodeRabbit fs:write decodes Base64 and writes it at a chosen file offset.
37 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cross-platform Node.js remote-access trojan used for cyberespionage. It is delivered in trojanized developer coding-challenge projects and supports host reconnaissance, process execution and management, file operations, network-configuration collection, C2 reconfiguration, and execution of C2-supplied Node.js scripts. Variants establish OS-specific persistence and use encrypted HTTPS C2 communications; the third variant also adds Outlook-address harvesting, malicious VS Code-extension persistence, and Git-hook injection.
A cross-platform Node.js RAT targeting Windows, Linux, macOS, and WSL. It establishes persistence using OS-specific mechanisms, communicates with Azure- and Cloudflare-hosted C2 infrastructure using encrypted HTTP(S), supports host and network reconnaissance, arbitrary command/script execution, process management, and file operations. Its third variant adds C2 reconfiguration, Outlook email harvesting, malicious VS Code-extension persistence, and Git-hook injection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.