NodeRabbit is a Node.js-based remote-access trojan targeting Windows, Linux, and macOS. It is associated with the Iran-linked cyberespionage actor Mirage Kitten, also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore. Its deployment has targeted software developers in financial technology, aviation, and aerospace organizations across the Middle East and Africa, with confirmed infections in Afghanistan, Egypt, and Ethiopia.
Operators distribute NodeRabbit through recruitment-themed spearphishing on LinkedIn and other employment platforms. Fake recruiters persuade targets to download and execute trojanized coding-assessment archives hosted on Amazon S3. These projects contain malicious Node.js packages bundled locally rather than published to the public npm registry. Importing a malicious dependency launches the implant as a detached background process. Short assessment deadlines encourage execution with limited scrutiny.
NodeRabbit collects host and network information, enumerates processes and directories, executes shell commands and attacker-supplied Node.js scripts, manipulates files, and transfers data. It derives a host-specific agent identifier from system attributes and encrypts command-and-control communications using AES-256-GCM. Its infrastructure includes Azure-hosted command servers. Later variants support enterprise proxy discovery and authenticated tunneling, command-server replacement, process termination, mounted-volume enumeration, discovery of development projects and Git repositories, and extraction of Outlook account addresses from local artifacts. The command set expanded from 11 commands in an initial variant to 23 in a later variant.
Anti-analysis features inspect system resources, uptime, host and user names, and analysis tools; suspicious environments can cause the implant to exit without contacting its command server. Persistence mechanisms include Windows autorun entries or scheduled tasks, Linux cron entries, and macOS LaunchAgents. Advanced variants also install a counterfeit Visual Studio Code extension and modify Git hooks to relaunch the implant during routine development activity, with attempts to disable Visual Studio Code Workspace Trust.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
NodeRabbit gathers host details, communicates with remote servers and can run commands, list processes, browse files and transfer data.
NodeRabbit gathers host and network details, lists processes, runs shell commands, and manipulates files.
NodeRabbit is a cross-platform RAT developed using Node.js... More advanced variants introduce anti-analysis checks, corporate proxy support, expanded C2 capabilities, Outlook account discovery, and persistence through malicious Visual Studio Code extensions and Git hooks.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Its first line instead imported colorized_terminal version 2.1.0, a malicious package bundled inside node_modules rather than obtained from npm; loading it launched NodeRabbit from a hidden cache path.
“The first line of server.js imported a malicious npm package named colorized_terminal... attackers bundled it directly inside the archive's node_modules directory.”
NodeRabbit gathers host and network details, lists processes, runs shell commands... PollCat provides ... shell access, and arbitrary JavaScript execution.
Les chemins incluent ~/Library/LaunchAgents/com.microsoft.edgeupdate.plist, com.intel.dsa.helper et com.harsh.requireobject.plist.
Les chemins incluent ~/Library/LaunchAgents/com.microsoft.edgeupdate.plist, com.intel.dsa.helper et com.harsh.requireobject.plist.
“NodeRabbit can create an extension masquerading as GitHub Copilot Helper,” and actors “incorporated a targeted organization's name into Azure subdomains.”
La persistance est masquée en Microsoft Edge Update ou Intel DSA; une fausse extension VS Code est nommée GitHub Copilot Helper.
T1016 — System Network Configuration Discovery (Discovery).
NodeRabbit gathers host and network details... PollCat provides file transfers, system inventory...
Its third variant expands to 23 commands and searches for Outlook addresses, mounted drives, development projects, and Git repositories.
“New functionality includes... Outlook account address discovery from OST and PST artifacts.”
Newer versions check for analysis environments... PollCat ... [checks] for traces of security products.
“[NodeRabbit] communicates with Azure-hosted C2 infrastructure using encrypted API requests.”
La variante Égypte prend en charge les proxys NTLM/Negotiate via curl.exe; cette délégation proxy est aussi citée comme similarité avec Retrograde/MiniFast.
“The malware supports HTTP CONNECT tunneling and can attempt Basic, NTLM, or Negotiate proxy authentication.”
[The] coding assessment [is] hosted on a completely legitimate-looking Amazon S3 link.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cross-platform remote-access trojan for Windows, Linux, and macOS. It inventories hosts and networks, enumerates processes, executes shell commands, manipulates files, evades analysis, handles enterprise proxies, rotates C2 servers, and searches for Outlook addresses, mounted drives, development projects, and Git repositories. It can persist or relaunch through a malicious VS Code extension and Git post-merge/post-checkout hooks.
Cross-platform remote access trojan delivered through fake recruitment coding assessments targeting developers. A bundled malicious package, colorized_terminal version 2.1.0, launches it from a hidden cache path. It collects system information, executes commands, and manipulates files. Newer variants detect analysis environments, support enterprise proxies, and switch command servers. Its third variant supports 23 commands and searches for Outlook addresses, mounted drives, development projects, and Git repositories. Persistence mechanisms include a malicious Visual Studio Code extension disguised as GitHub Copilot Helper and launchers inserted into Git hooks.
A Node.js/JavaScript cross-platform remote-access trojan targeting developer workstations. It supports encrypted Azure-hosted C2, host and network reconnaissance, arbitrary shell and Node.js command execution, file operations, process enumeration, and persistence on Windows, Linux, and macOS. Advanced variants evade analysis environments, authenticate through enterprise proxies, enumerate Outlook accounts, alter C2 servers, and persist through malicious Visual Studio Code extensions, Windows Run keys, and Git post-merge/post-checkout hooks.
A cross-platform Node.js implant delivered in trojanized coding challenges. It establishes a background process and encrypted command-and-control communications, performs sandbox/analysis-environment checks, and later variants add expanded command support, malicious VS Code-extension deployment, and Git-hook persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.