Cybercriminals are posing as recruiters to turn routine job interviews into malware traps for software developers.
Their latest campaign delivers two cross-platform remote access tools, NodeRabbit and PollCat, through coding challenges that look like genuine take-home tests.
The activity has reached victims in aviation, aerospace and financial technology across Egypt, Ethiopia and Afghanistan.
It also shows how a seemingly ordinary project download can give attackers a foothold on a developer workstation, where source code, cloud credentials and corporate access may be within reach.
Researchers at Securelist identified the previously undocumented NodeRabbit and PollCat families while tracking the Mirage Kitten group.
Securelist said in a report shared with Cyber Security News (CSN) that this is the group’s first publicly documented use of Node.js and JavaScript implants.
The shift matters because the malware runs on Windows, Linux and macOS, matching the mixed environments common in engineering teams.

It also extends an established social-engineering pattern seen in earlier fake recruiter campaigns, but combines it with more persistent access and developer-focused tricks.
Hackers Pose as Recruiters and Send Fake Coding Tests
The infection starts with a recruiter persona on LinkedIn or another job-search service. The target is offered an engineering role and sent a link to a coding assessment stored in an Amazon S3 bucket, then pressured to download and run the project quickly.
One lure, named TaskFlow, claimed to be a frontend bug-fixing exercise. Its README set a three-hour limit, told candidates not to use AI assistants and insisted that the server.js file was already correct. Those instructions steered attention away from the altered code.
The first line of server.js imported colorized_terminal version 2.1.0, a malicious package bundled inside node_modules rather than published on npm.

Importing it quietly launched NodeRabbit in the background from a hidden cache path, echoing risks in the binding.gyp supply chain attack, where normal developer actions triggered code execution.
Other archives used a second tainted package, pretty-log, to start more advanced NodeRabbit variants. The researchers recovered related samples from systems in Afghanistan, Egypt and Ethiopia, linking the campaign to a broader effort against organizations in the Middle East and Africa.
NodeRabbit and PollCat Expand Access
NodeRabbit gathers host details, communicates with remote servers and can run commands, list processes, browse files and transfer data.
Its later version also searches developer project locations, can add a fake editor extension and injects launchers into Git hooks, so routine development work may restart the malware.
PollCat arrives through a separate React-based assessment called RankChallenge-react. The project asks the candidate to run an installation command and then presents an expiring, recruiter-supplied one-time code, a design that builds urgency while its hidden component begins contacting attacker infrastructure.
Once active, PollCat can execute shell commands, move or delete files, collect system information and move files between the victim and its operators.

It establishes persistence through scheduled tasks on Windows, cron jobs on Linux, or a LaunchAgent on macOS. The outcome resembles the compromised node-ipc package, where a loaded JavaScript module exposed developer secrets and enabled remote control.
Developers should treat unsolicited assessment archives as untrusted software, even when the sender has a convincing professional profile.
Confirm the opportunity through an employer’s official channel, inspect dependencies and startup files before running a project, and use an isolated environment that contains no production credentials or private repositories.
Teams should also review recent coding-test downloads, check for unexpected scheduled tasks, editor extensions and changed Git hooks, and rotate credentials stored on a machine that ran a suspicious challenge.
That caution is especially important after the malicious undicy-http package campaign, which similarly showed how a deceptive JavaScript package can persist and expose sensitive data.
Employers should recognize that recruiting now sits inside the attack surface. Security teams can give candidates safe testing environments and simple ways to verify whether a recruiter, assignment and download link are legitimate.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| File hash, MD5 | CBAAF0900A13F28E380F49ADECEC932C |
FrontEnd-Task.zip |
| File hash, MD5 | 1EA83E4E4592B01E4ACAB63EB867BEE5 |
Front-Technical-Challenge.zip |
| File hash, MD5 | 366515822D5AC1CC500711EF57A2E32E |
Task-FullStack.zip |
| File hash, MD5 | CF449F1992C2819E62AC44A0B06AC2E7 |
fullstack-1536.zip |
| File hash, MD5 | E95A4366686E3F786EA3C056FAB5B0DA |
webapp76592.zip |
| File hash, MD5 | DE5AF16A3757EF700B01DC34D67079AE |
webapp76531.zip |
| File hash, MD5 | BE086789568441D0D7E4679AEE51F566 |
challenges-17831.zip |
| File hash, MD5 | E259C5EDF158AAC4CFE14F77DDD0B196 |
challenges-17832.zip |
| File hash, MD5 | 291AC3ABE73C5158E59A437B75D5F0AA |
Project-1802.zip |
| File hash, MD5 | 0962F56D7EC69F4F2A0162DCBE22116B |
Case-34234.zip |
| File hash, MD5 | 795E053A990A1569FFDCB57F48F6D085 |
RankChallenge-react-6uJSX3-main.zip |
| File hash, MD5 | 810F8E3B88EB05F710C09552941D6F56 |
Retrograde/MiniFast native DLL backdoor reference sample |
| URL | https://oracle-challenge.s3[.]us-east-1.amazonaws[.]com/Front-Technical-Challenge.zip |
Trojanized coding-challenge archive download |
| Domain | oracle-challenge.s3[.]us-east-1.amazonaws[.]com |
Host for the coding-challenge archive |
| Domain | naturalapplication.azurewebsites[.]net |
NodeRabbit command-and-control infrastructure |
| Domain | retaildemo.azurewebsites[.]net |
NodeRabbit command-and-control infrastructure |
| Domain | tubitak.azurewebsites[.]net |
NodeRabbit command-and-control infrastructure |
| Domain | rgbteller.azurewebsites[.]net |
NodeRabbit command-and-control infrastructure |
| Domain | wslwebui.azurewebsites[.]net |
NodeRabbit command-and-control infrastructure |
| Domain | plugplay.azurewebsites[.]net |
NodeRabbit command-and-control infrastructure |
| Domain | crossdwm.azurewebsites[.]net |
NodeRabbit command-and-control infrastructure |
| Domain | wdisystem.azurewebsites[.]net |
NodeRabbit command-and-control infrastructure |
| Domain | wslmenus.azurewebsites[.]net |
NodeRabbit command-and-control infrastructure |
| Domain | dnshnsdev.azurewebsites[.]net |
NodeRabbit command-and-control infrastructure |
| Domain | hpjumpsrv.azurewebsites[.]net |
NodeRabbit command-and-control infrastructure |
| Domain | storview.azurewebsites[.]net |
NodeRabbit command-and-control infrastructure |
| Domain | healthcomfsdpower[.]com |
NodeRabbit command-and-control infrastructure |
| Domain | visitfinancedentists[.]com |
NodeRabbit command-and-control infrastructure |
| Domain | kyrasey-f8hfexa5cqamh7fk.westeurope-01.azurewebsites[.]net |
NodeRabbit command-and-control infrastructure |
| Domain | greenyjsgfd.azurewebsites[.]net |
NodeRabbit command-and-control infrastructure |
| Domain | helptellerbls.azurewebsites[.]net |
NodeRabbit command-and-control infrastructure |
| Domain | timedrv.azurewebsites[.]net |
NodeRabbit command-and-control infrastructure |
| Domain | userwellgtfs.azurewebsites[.]net |
NodeRabbit command-and-control infrastructure |
| Domain | hecowime-aqdphyd4bbdef6es.westeurope-01.azurewebsites[.]net |
NodeRabbit command-and-control infrastructure |
| Domain | msmanagementgrp[.]com |
NodeRabbit command-and-control infrastructure |
| Domain | msmanagementgrpmedia[.]com |
NodeRabbit command-and-control infrastructure |
| URL | https://lifespotify[.]com/api/users/b879746e-fed9-4211-a6da-4d8223681267/otp/validate |
PollCat lure OTP-validation endpoint |
| Domain | lifespotify[.]com |
PollCat infrastructure and OTP-validation host |
| Domain | gamebarapp.azurewebsites[.]net |
PollCat command-and-control infrastructure |
| Domain | gamebarappinformation.azurewebsites[.]net |
PollCat command-and-control infrastructure |
| Domain | sahi-finance[.]com |
PollCat command-and-control infrastructure |
| Domain | healthful-hub[.]com |
Additional infrastructure attributed to Mirage Kitten |
| Domain | neumedicahealthcare[.]com |
Additional infrastructure attributed to Mirage Kitten |
| Domain | optimumhealthcredit[.]com |
Additional infrastructure attributed to Mirage Kitten |
| Domain | healthfullyrecipes[.]com |
Additional infrastructure attributed to Mirage Kitten |
| Domain | Refreshhealthandwellness[.]com |
Additional infrastructure attributed to Mirage Kitten |
| Domain | healthvitalitycare[.]com |
Additional infrastructure attributed to Mirage Kitten |
| Domain | aceofspadesmanagement[.]com |
Additional infrastructure attributed to Mirage Kitten |
| Domain | glmediaagency[.]com |
Additional infrastructure attributed to Mirage Kitten |
| Domain | digimediaskill[.]com |
Additional infrastructure attributed to Mirage Kitten |
| Domain | healthyweightplan[.]com |
Additional infrastructure attributed to Mirage Kitten |
| Domain | mens-health-online[.]com |
Additional infrastructure attributed to Mirage Kitten |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
The post Hackers Pose as Recruiters and Send Fake Coding Tests to Infect Software Developers appeared first on Cyber Security News.
