Fake Recruiter Lure Drops NodeRabbit RAT

Securelist · High sophistication
Last updated September 1, 2026

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers control the machine and steal data.

How the Attack Worked

The campaign, attributed to a group tracked as Mirage Kitten, began with fake recruiter accounts reaching out to software engineers on LinkedIn and other job search platforms. A threat actor posing as a talent acquisition specialist at a major technology company contacted a target, advertised a job opening, and pressured them to complete a technical assessment quickly.

The assessment was delivered as a ZIP archive, Front-Technical-Challenge.zip, hosted on an Amazon S3 bucket rather than an official hiring portal. Inside was a Node.js project accompanied by a README instructing the candidate to review the application and fix frontend defects. The README specifically claimed that server.js was bug free and should not be modified, which conveniently directed attention away from the one file the attackers had altered.

When the candidate ran the project, the first line of server.js imported a trojanized npm package. The package was bundled directly inside the archive's node_modules directory instead of being published to the npm registry, making it harder to spot through normal dependency checks. Importing it silently launched an implant as a detached background process, installing the NodeRabbit remote access trojan and giving attackers control of the machine.

Why It Succeeded

The lure combined several pressure points that reduced scrutiny. Candidates were pushed to act immediately, given a strict three hour time limit, and told not to use AI assistants during review. The claim that a specific file was bug free discouraged candidates from examining the exact location of the malicious code. Because the challenge was framed as a normal part of a hiring process, most of these instructions appeared reasonable rather than suspicious.

What to Watch For

  • Unsolicited recruiter contact followed by pressure to download and run code quickly
  • Assessment files hosted on generic cloud storage links instead of an official hiring platform
  • Instructions that tell you not to modify or review a particular file
  • Unusual rules such as strict time limits or bans on assistive tools during review
  • Unfamiliar packages bundled directly in node_modules rather than installed from the public registry

Building Resistance

Organizations can reduce exposure by training developers and hiring teams to verify recruiter identity and job offers through official company channels before opening any attachment. Coding challenges from unknown sources should be reviewed in a sandbox rather than run directly on a work machine, with particular attention paid to bundled dependencies and any file the instructions say not to touch. Building awareness of these supply chain style tricks helps candidates recognize manipulation attempts embedded in what looks like a routine technical assessment.

Key findings

  • Mirage Kitten used fake recruiter personas on LinkedIn/job platforms to deliver trojanized coding challenge archives.
  • The lure was a ZIP file presented as a technical assessment (e.g., “Front-Technical-Challenge.zip”) hosted on Amazon S3.
  • The README instructed candidates to focus on frontend defects and claimed “server.js was bug-free,” steering attention away from the modified file.
  • Trojanized npm packages (e.g., colorized_terminal, pretty-log) embedded inside the ZIP executed the RAT when the project was run.
  • NodeRabbit used Azure-hosted C2 infrastructure and implemented persistence on Windows, Linux, and macOS; later variants added proxy support and developer-workflow persistence (e.g., fake VS Code extension, Git hook injection).

Who’s being targeted

  • Commonly targeted roles: Software Engineers / Developers, Engineering Managers, HR / Talent Acquisition, IT Helpdesk / Endpoint Security, Security Awareness / GRC teams.
  • Affected industries: Financial Technology (FinTech), Aviation, Technology / Software Development, Professional Services (Engineering/IT), Government and critical infrastructure (regional targeting context: Middle East and Africa).
  • Attack channels: linkedin, website.
  • Impersonated: Talent acquisition specialist / recruiter at a major technology company, Hiring team / technical assessment platform.

Red flags to watch for

  • Pressure to act immediately (rushed download/run request)
  • “Assessment” delivered as a ZIP from a generic cloud bucket rather than an official hiring portal
  • Instructions that discourage safeguards (e.g., bans on AI assistants) and direct you away from certain files
  • A bundled dependency inside node_modules instead of a normal, verifiable install from official sources
  • README claims a sensitive file is “bug-free and should not be modified,” discouraging review
  • Unusual rules like a strict time limit and banning AI assistants
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the fake recruiter attack deliver malware?

Attackers posed as recruiters on LinkedIn and job platforms, offering a role and sending a technical assessment ZIP hosted on Amazon S3. Running the included Node.js project silently launched the NodeRabbit remote access trojan.

What made this coding challenge lure convincing?

The README instructed candidates to focus on frontend defects and claimed the backend file server.js was bug free, steering attention away from the file the attackers had actually modified.

What technical trick hid the malicious code?

The attackers bundled a trojanized npm package directly inside the node_modules folder rather than publishing it to the npm registry, so importing it silently launched the implant as a background process.

What should developers do differently after this attack?

Verify recruiter identity and job offers through official company channels, avoid running unsolicited coding challenges without review or sandboxing, and be wary of rules that discourage scrutiny such as time limits or bans on reviewing certain files.

Read the video transcript

You get a LinkedIn DM from a “talent acquisition specialist” at a big-name tech company, great job, quick technical assessment, just run their ZIP. You download Front-Technical-Challenge.zip from an Amazon S3 bucket, open the Node project, and the README says: three-hour limit, no AI tools, and “server.js is bug-free, do not touch it.” That’s exactly where the NodeRabbit RAT is hiding. Run it, and those trojanized npm packages quietly install NodeRabbit, call back to Azure, and sit on your Windows, macOS, or Linux box with persistence, watching your dev work, stealing data, even lurking in fake VS Code extensions or Git hooks. Here’s the move: before you run any recruiter-sent coding ZIP, verify the recruiter and role through the company’s official site, and get that project reviewed or sandboxed first.

Similar attacks

Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
OkoBot Tricks Crypto Users Into Running Commands

OkoBot Tricks Crypto Users Into Running Commands

Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that trick them into running PowerShell commands, and via GitHub repos posing as legitimate software downloads. The malware then steals wallet…

July 16, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Fake Claude & Perplexity Lures Push Malware

Fake Claude & Perplexity Lures Push Malware

Sophos reports real incidents where attackers impersonated well-known AI brands (especially Claude) to trick people into installing malware. The lures included polished fake installer pages that instruct victims to copy/paste commands, and browser extensions that look legitimate via high ratings…

August 21, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a…

August 12, 2026