
Findings and evidence
Kaspersky reports NodeRabbit and PollCat, two cross-platform malware families encountered while investigating Mirage Kitten activity. The analysis links trojanized recruitment coding challenges to JavaScript and Node.js components found in several countries.
Why it matters
Developer workstations hold relevant evidence in project archives, dependency records, editor state and process telemetry. Preserve the project as received before analysis and examine its provenance in a controlled environment.
Scope and limits
Code and behavior similarities underpin the publisher’s attribution. A JavaScript dependency or a recruitment exercise by itself is not a reliable malicious indicator.
Primary source
Kaspersky / Securelist: original publication. Source published 2026-09-01. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.