Hackers Pose as Recruiters and Send Fake Coding Tests to Infect Software Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Cybercriminals are posing as recruiters to turn routine job interviews into malware traps for software developers.

Their latest campaign delivers two cross-platform remote access tools, NodeRabbit and PollCat, through coding challenges that look like genuine take-home tests.

The activity has reached victims in aviation, aerospace and financial technology across Egypt, Ethiopia and Afghanistan.

It also shows how a seemingly ordinary project download can give attackers a foothold on a developer workstation, where source code, cloud credentials and corporate access may be within reach.

Researchers at Securelist identified the previously undocumented NodeRabbit and PollCat families while tracking the Mirage Kitten group.

Securelist said in a report shared with Cyber Security News (CSN) that this is the group’s first publicly documented use of Node.js and JavaScript implants.

The shift matters because the malware runs on Windows, Linux and macOS, matching the mixed environments common in engineering teams.

TaskFlow (Source - Securelist)
TaskFlow (Source – Securelist)

It also extends an established social-engineering pattern seen in earlier fake recruiter campaigns, but combines it with more persistent access and developer-focused tricks.

Hackers Pose as Recruiters and Send Fake Coding Tests

The infection starts with a recruiter persona on LinkedIn or another job-search service. The target is offered an engineering role and sent a link to a coding assessment stored in an Amazon S3 bucket, then pressured to download and run the project quickly.

One lure, named TaskFlow, claimed to be a frontend bug-fixing exercise. Its README set a three-hour limit, told candidates not to use AI assistants and insisted that the server.js file was already correct. Those instructions steered attention away from the altered code.

The first line of server.js imported colorized_terminal version 2.1.0, a malicious package bundled inside node_modules rather than published on npm.

Rules and time limit included in the trojanized coding challenge app README file (Source - Securelist)
Rules and time limit included in the trojanized coding challenge app README file (Source – Securelist)

Importing it quietly launched NodeRabbit in the background from a hidden cache path, echoing risks in the binding.gyp supply chain attack, where normal developer actions triggered code execution.

Other archives used a second tainted package, pretty-log, to start more advanced NodeRabbit variants. The researchers recovered related samples from systems in Afghanistan, Egypt and Ethiopia, linking the campaign to a broader effort against organizations in the Middle East and Africa.

NodeRabbit and PollCat Expand Access

NodeRabbit gathers host details, communicates with remote servers and can run commands, list processes, browse files and transfer data.

Its later version also searches developer project locations, can add a fake editor extension and injects launchers into Git hooks, so routine development work may restart the malware.

PollCat arrives through a separate React-based assessment called RankChallenge-react. The project asks the candidate to run an installation command and then presents an expiring, recruiter-supplied one-time code, a design that builds urgency while its hidden component begins contacting attacker infrastructure.

Once active, PollCat can execute shell commands, move or delete files, collect system information and move files between the victim and its operators.

The bundled .env file (Source - Securelist)
The bundled .env file (Source – Securelist)

It establishes persistence through scheduled tasks on Windows, cron jobs on Linux, or a LaunchAgent on macOS. The outcome resembles the compromised node-ipc package, where a loaded JavaScript module exposed developer secrets and enabled remote control.

Developers should treat unsolicited assessment archives as untrusted software, even when the sender has a convincing professional profile.

Confirm the opportunity through an employer’s official channel, inspect dependencies and startup files before running a project, and use an isolated environment that contains no production credentials or private repositories.

Teams should also review recent coding-test downloads, check for unexpected scheduled tasks, editor extensions and changed Git hooks, and rotate credentials stored on a machine that ran a suspicious challenge.

That caution is especially important after the malicious undicy-http package campaign, which similarly showed how a deceptive JavaScript package can persist and expose sensitive data.

Employers should recognize that recruiting now sits inside the attack surface. Security teams can give candidates safe testing environments and simple ways to verify whether a recruiter, assignment and download link are legitimate.

Indicators of compromise (IoCs):-

Type Indicator Description
File hash, MD5 CBAAF0900A13F28E380F49ADECEC932C FrontEnd-Task.zip
File hash, MD5 1EA83E4E4592B01E4ACAB63EB867BEE5 Front-Technical-Challenge.zip
File hash, MD5 366515822D5AC1CC500711EF57A2E32E Task-FullStack.zip
File hash, MD5 CF449F1992C2819E62AC44A0B06AC2E7 fullstack-1536.zip
File hash, MD5 E95A4366686E3F786EA3C056FAB5B0DA webapp76592.zip
File hash, MD5 DE5AF16A3757EF700B01DC34D67079AE webapp76531.zip
File hash, MD5 BE086789568441D0D7E4679AEE51F566 challenges-17831.zip
File hash, MD5 E259C5EDF158AAC4CFE14F77DDD0B196 challenges-17832.zip
File hash, MD5 291AC3ABE73C5158E59A437B75D5F0AA Project-1802.zip
File hash, MD5 0962F56D7EC69F4F2A0162DCBE22116B Case-34234.zip
File hash, MD5 795E053A990A1569FFDCB57F48F6D085 RankChallenge-react-6uJSX3-main.zip
File hash, MD5 810F8E3B88EB05F710C09552941D6F56 Retrograde/MiniFast native DLL backdoor reference sample
URL https://oracle-challenge.s3[.]us-east-1.amazonaws[.]com/Front-Technical-Challenge.zip Trojanized coding-challenge archive download
Domain oracle-challenge.s3[.]us-east-1.amazonaws[.]com Host for the coding-challenge archive
Domain naturalapplication.azurewebsites[.]net NodeRabbit command-and-control infrastructure
Domain retaildemo.azurewebsites[.]net NodeRabbit command-and-control infrastructure
Domain tubitak.azurewebsites[.]net NodeRabbit command-and-control infrastructure
Domain rgbteller.azurewebsites[.]net NodeRabbit command-and-control infrastructure
Domain wslwebui.azurewebsites[.]net NodeRabbit command-and-control infrastructure
Domain plugplay.azurewebsites[.]net NodeRabbit command-and-control infrastructure
Domain crossdwm.azurewebsites[.]net NodeRabbit command-and-control infrastructure
Domain wdisystem.azurewebsites[.]net NodeRabbit command-and-control infrastructure
Domain wslmenus.azurewebsites[.]net NodeRabbit command-and-control infrastructure
Domain dnshnsdev.azurewebsites[.]net NodeRabbit command-and-control infrastructure
Domain hpjumpsrv.azurewebsites[.]net NodeRabbit command-and-control infrastructure
Domain storview.azurewebsites[.]net NodeRabbit command-and-control infrastructure
Domain healthcomfsdpower[.]com NodeRabbit command-and-control infrastructure
Domain visitfinancedentists[.]com NodeRabbit command-and-control infrastructure
Domain kyrasey-f8hfexa5cqamh7fk.westeurope-01.azurewebsites[.]net NodeRabbit command-and-control infrastructure
Domain greenyjsgfd.azurewebsites[.]net NodeRabbit command-and-control infrastructure
Domain helptellerbls.azurewebsites[.]net NodeRabbit command-and-control infrastructure
Domain timedrv.azurewebsites[.]net NodeRabbit command-and-control infrastructure
Domain userwellgtfs.azurewebsites[.]net NodeRabbit command-and-control infrastructure
Domain hecowime-aqdphyd4bbdef6es.westeurope-01.azurewebsites[.]net NodeRabbit command-and-control infrastructure
Domain msmanagementgrp[.]com NodeRabbit command-and-control infrastructure
Domain msmanagementgrpmedia[.]com NodeRabbit command-and-control infrastructure
URL https://lifespotify[.]com/api/users/b879746e-fed9-4211-a6da-4d8223681267/otp/validate PollCat lure OTP-validation endpoint
Domain lifespotify[.]com PollCat infrastructure and OTP-validation host
Domain gamebarapp.azurewebsites[.]net PollCat command-and-control infrastructure
Domain gamebarappinformation.azurewebsites[.]net PollCat command-and-control infrastructure
Domain sahi-finance[.]com PollCat command-and-control infrastructure
Domain healthful-hub[.]com Additional infrastructure attributed to Mirage Kitten
Domain neumedicahealthcare[.]com Additional infrastructure attributed to Mirage Kitten
Domain optimumhealthcredit[.]com Additional infrastructure attributed to Mirage Kitten
Domain healthfullyrecipes[.]com Additional infrastructure attributed to Mirage Kitten
Domain Refreshhealthandwellness[.]com Additional infrastructure attributed to Mirage Kitten
Domain healthvitalitycare[.]com Additional infrastructure attributed to Mirage Kitten
Domain aceofspadesmanagement[.]com Additional infrastructure attributed to Mirage Kitten
Domain glmediaagency[.]com Additional infrastructure attributed to Mirage Kitten
Domain digimediaskill[.]com Additional infrastructure attributed to Mirage Kitten
Domain healthyweightplan[.]com Additional infrastructure attributed to Mirage Kitten
Domain mens-health-online[.]com Additional infrastructure attributed to Mirage Kitten

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Hackers Pose as Recruiters and Send Fake Coding Tests to Infect Software Developers appeared first on Cyber Security News.