Kaspersky identified NodeRabbit and PollCat, two previously undocumented cross-platform remote access trojans deployed by the Mirage Kitten APT group. NodeRabbit is a Node.js RAT delivered through trojanized coding challenge archives on job search platforms, communicating with Azure-hosted C2 endpoints using AES-256-GCM encryption. PollCat is an obfuscated JavaScript RAT using HTTP polling with a custom C2 protocol that treats HTTP 400 responses as successful registration and shares structural similarities with the Retrograde/MiniFast backdoor. Both malware families target Windows, Linux, and macOS, with NodeRabbit variant 3 introducing persistence via fake VS Code extensions and Git hook injection.
Node.js RAT
2 posts
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan Two beta releases of the @joyfill npm packages were compromised at build time with a multi-layered obfuscated implant that triggers on module import rather than via npm lifecycle hooks. The implant resolves payloads through Tron/Aptos/BNB Smart Chain transactions to fetch a 77KB Node.js RAT (Socket.IO C2, ss_* command set) and, via a detached process, a separate bootstrap that can deploy a Python infostealer targeting credentials, browser data, and wallet extensions. Code and operational indicators tie the loader to the PolinRider family and the final payload to the DEV#POPPER campaign, with the compromise attributed to maintainer-side access rather than a fake-repo lure.