Kaspersky uncovered two previously undocumented malware families, NodeRabbit and PollCat, that Mirage Kitten is delivering through trojanized coding-challenge archives on LinkedIn and other job platforms. The samples surfaced on systems in Afghanistan, Egypt, and Ethiopia, and Kaspersky says this is the group’s first public use of Node.js and JavaScript malware.
The lure looks like a normal take-home engineering test, but the archive has been altered so a project file quietly loads attacker code when it runs. NodeRabbit is a Node.js remote access trojan, and PollCat is obfuscated JavaScript, so the same package can target Windows, Linux, or macOS and reach whatever code, credentials, or context a candidate machine can access during the exercise.
The exposure sits in the hiring workflow itself: if your teams exchange candidate assignments as archives or shared projects, the trust you give those files becomes part of the attack surface. Standard filtering may not flag them because they arrive dressed as routine recruiting work, not as obviously malicious attachments.