How to remove NodeRabbit RAT from the operating system
TrojanAlso Known As: NodeRabbit remote access trojan
Get free scan and check if your device is infected.
Remove it nowTo use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
What kind of malware is NodeRabbit?
NodeRabbit is a Remote Access Trojan (RAT) written in Node.js. It lets attackers secretly run commands, manage files, collect information about the device and network, and load additional code on infected computers. The malware is cross-platform and works on Windows, Linux, and macOS.
Kaspersky researchers discovered NodeRabbit while investigating infections linked to Mirage Kitten, an Iran-linked cyberespionage group also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore. As summarized by PolySwarm, the group lures software developers with fake job offers and booby-trapped coding tests.

NodeRabbit overview
Mirage Kitten has historically targeted strategically important organizations, mostly in the Middle East, with a focus on aerospace, aviation, and defense. In this campaign, the attackers went after the fintech, aviation, and aerospace sectors in the Middle East and Africa, including targets in Egypt, Ethiopia, and Afghanistan.
It is worth noting that NodeRabbit and its sibling PollCat are the group's first publicly documented malware built with Node.js and JavaScript. That choice fits the targets well - developers already have Node.js installed, so the malware blends in with their everyday tools.
Once running, NodeRabbit connects to its Command and Control (C2) server, which is hosted on Microsoft Azure. Each infected device is identified by its hostname, username, operating system version, architecture, and MAC address.
The requests the malware sends to the server are protected with AES-256-GCM encryption. This makes the traffic much harder for security tools and network administrators to inspect.
NodeRabbit's features
Kaspersky identified three versions of NodeRabbit. The first supported 11 commands, which let operators gather host and network information, list running processes, execute arbitrary shell commands, and manipulate files and folders. It could also change how often it checks in with the server and run additional Node.js scripts.
The third version expanded the command set to 23 commands. New additions include listing drives and volumes, launching and terminating processes, and a command called agent:servers that swaps the active C2 servers and saves the new configuration to disk. In other words, the attackers can move infected machines to new infrastructure whenever their old servers are blocked or taken down.
Also, this version can discover Microsoft Outlook email account addresses by examining OST and PST data files stored on the computer. For an espionage group, this is a quick way to learn which work email accounts the victim uses.
Anti-analysis and corporate network support
The second version of NodeRabbit was built with company networks in mind. Before doing anything, it checks whether it is running inside a sandbox or on a researcher's machine, looking for signs such as a small amount of memory or usernames commonly used by malware analysts.
If such signs are found, the malware sends harmless requests to Google, Microsoft, and Cloudflare and then exits. This is likely meant to make the run look like ordinary network activity rather than something suspicious.
This variant also knows how to work with corporate proxy servers. It reads proxy settings from environment variables, tunnels its traffic through HTTP CONNECT, and supports Basic, NTLM, and Negotiate proxy authentication. As a result, NodeRabbit can reach its operators even from networks where internet access goes through a company proxy.
Persistence through developer tools
The third version of NodeRabbit abuses developer tools to stay on the system. It creates a malicious Visual Studio Code extension disguised as GitHub Copilot Helper and reuses a trusted publisher name taken from extensions already installed on the device. It also tries to disable VS Code's Workspace Trust protection.
When loaded, the fake extension launches NodeRabbit as a separate, detached Node.js process. On top of that, the malware injects launchers into Git repository hooks, specifically post-merge and post-checkout, so routine actions like pulling code or switching branches start it again.
Essentially, the victim's normal development workflow becomes the trigger for the malware. Deleting the main NodeRabbit file alone may not be enough, since the fake extension and the modified Git hooks can bring it back.
| Name | NodeRabbit remote access trojan |
| Threat Type | Remote Access Trojan (RAT), Backdoor |
| Detection Names | Avast (Script:SNH-gen [Trj]), Combo Cleaner (Trojan.MirageKitten.22), Emsisoft (Trojan.MirageKitten.22 (B)), Kaspersky (Trojan.JS.MirageKitten.b), McAfee Scanner (Ti!123289B3680C), Full List (VirusTotal) |
| Symptoms | Remote Access Trojans are designed to stealthily infiltrate the victim's computer and remain silent, and thus no particular symptoms are clearly visible on an infected machine. |
| Distribution methods | Fake job offers, trojanized coding challenges, malicious npm packages, social engineering. |
| Damage | Stolen passwords and banking information, identity theft, the victim's computer added to a botnet, additional infections, monetary loss, account hijacking. |
| Malware Removal (Windows) |
To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner. Download Combo CleanerTo use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com. |
Conclusion
NodeRabbit gives attackers remote control over infected computers, allowing them to run commands, handle files, gather information, and execute further code. Its encrypted communication, anti-analysis checks, and persistence through VS Code and Git make it a serious espionage threat to developers and the companies they work for. If NodeRabbit is present on your device, it should be removed immediately.
More examples of RATs are SnakeBiteAgent, PackClient, and E4del.
How did NodeRabbit infiltrate my computer?
NodeRabbit is spread through fake job offers. The attackers pose as recruiters on LinkedIn and job-search platforms and approach software engineers with appealing opportunities. As part of the supposed hiring process, the victim receives a technical assessment in the form of a downloadable coding project.
One of these lures, Front-Technical-Challenge.zip, contained a trojanized web application called TaskFlow. The first line of its server.js file imported a malicious npm package named colorized_terminal (version 2.1.0), which silently launched NodeRabbit when the project was started. Later variants were delivered the same way through a package called pretty-log.
The malicious package was bundled directly inside the archive's node_modules folder instead of being downloaded from the public npm registry, which helped it avoid detection. The attackers also set a three-hour deadline and told victims not to use AI assistants, most likely so that no AI tool would review the code and flag the hidden package.
More generally, cybercriminals distribute RATs and other malware through phishing emails, malicious attachments and links, fake download websites, malicious advertisements, pirated software, and software cracks.
How to avoid installation of malware?
Be cautious with unsolicited job offers, especially when a "recruiter" asks you to download and run a coding project under a tight deadline. Before running any unfamiliar code, review its dependencies (including anything already bundled in the node_modules folder) and consider testing it in an isolated virtual machine rather than on your main work device.
Also, avoid opening attachments and links in unexpected emails or messages, download software only from official websites, and stay away from pirated programs and cracks. Keep your operating system, applications, and extensions updated, and use reputable security software. If you believe that your computer is already infected, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate infiltrated malware.
Instant automatic malware removal:
Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:
DOWNLOAD Combo CleanerBy downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quick menu:
- What is NodeRabbit?
- STEP 1. Manual removal of NodeRabbit malware.
- STEP 2. Check if your computer is clean.
How to remove malware manually?
Manual malware removal is a complicated task - usually it is best to allow antivirus or anti-malware programs to do this automatically. To remove this malware we recommend using Combo Cleaner Antivirus for Windows.
If you wish to remove malware manually, the first step is to identify the name of the malware that you are trying to remove. Here is an example of a suspicious program running on a user's computer:

If you checked the list of programs running on your computer, for example, using task manager, and identified a program that looks suspicious, you should continue with these steps:
Download a program called Autoruns. This program shows auto-start applications, Registry, and file system locations:

Restart your computer into Safe Mode:
Windows XP and Windows 7 users: Start your computer in Safe Mode. Click Start, click Shut Down, click Restart, click OK. During your computer start process, press the F8 key on your keyboard multiple times until you see the Windows Advanced Option menu, and then select Safe Mode with Networking from the list.

Video showing how to start Windows 7 in "Safe Mode with Networking":
Windows 8 users: Start Windows 8 is Safe Mode with Networking - Go to Windows 8 Start Screen, type Advanced, in the search results select Settings. Click Advanced startup options, in the opened "General PC Settings" window, select Advanced startup.
Click the "Restart now" button. Your computer will now restart into the "Advanced Startup options menu". Click the "Troubleshoot" button, and then click the "Advanced options" button. In the advanced option screen, click "Startup settings".
Click the "Restart" button. Your PC will restart into the Startup Settings screen. Press F5 to boot in Safe Mode with Networking.

Video showing how to start Windows 8 in "Safe Mode with Networking":
Windows 10 users: Click the Windows logo and select the Power icon. In the opened menu click "Restart" while holding "Shift" button on your keyboard. In the "choose an option" window click on the "Troubleshoot", next select "Advanced options".
In the advanced options menu select "Startup Settings" and click on the "Restart" button. In the following window you should click the "F5" button on your keyboard. This will restart your operating system in safe mode with networking.

Video showing how to start Windows 10 in "Safe Mode with Networking":
Extract the downloaded archive and run the Autoruns.exe file.

In the Autoruns application, click "Options" at the top and uncheck "Hide Empty Locations" and "Hide Windows Entries" options. After this procedure, click the "Refresh" icon.

Check the list provided by the Autoruns application and locate the malware file that you want to eliminate.
You should write down its full path and name. Note that some malware hides process names under legitimate Windows process names. At this stage, it is very important to avoid removing system files. After you locate the suspicious program you wish to remove, right click your mouse over its name and choose "Delete".

After removing the malware through the Autoruns application (this ensures that the malware will not run automatically on the next system startup), you should search for the malware name on your computer. Be sure to enable hidden files and folders before proceeding. If you find the filename of the malware, be sure to remove it.

Reboot your computer in normal mode. Following these steps should remove any malware from your computer. Note that manual threat removal requires advanced computer skills. If you do not have these skills, leave malware removal to antivirus and anti-malware programs.
These steps might not work with advanced malware infections. As always it is best to prevent infection than try to remove malware later. To keep your computer safe, install the latest operating system updates and use antivirus software. To be sure your computer is free of malware infections, we recommend scanning it with Combo Cleaner Antivirus for Windows.
Frequently Asked Questions (FAQ)
My computer is infected with NodeRabbit malware, should I format my storage device to get rid of it?
Formatting will remove NodeRabbit, but it also wipes every file on the drive. Before going that far, scan the system with a reputable security tool such as Combo Cleaner. Developers should also review their VS Code extensions and Git hooks, since NodeRabbit can hide in both.
What are the biggest issues that NodeRabbit malware can cause?
NodeRabbit gives attackers a hidden foothold on the computer. They can run commands, access and change files, collect details about the system and network, and deploy more malware. For the victim, this can lead to stolen work data, compromised corporate accounts, espionage, and a wider breach of their employer's network.
What is the purpose of NodeRabbit malware?
NodeRabbit is a cyberespionage tool. Its purpose is to give the Mirage Kitten group lasting remote access to developers' machines so they can gather information, execute commands, and push additional payloads while staying unnoticed.
How did NodeRabbit malware infiltrate my computer?
NodeRabbit has been spread through fake job offers sent via LinkedIn and job-search platforms. Victims received coding tests like Front-Technical-Challenge.zip, which carried a malicious npm package (colorized_terminal or pretty-log) that launched the RAT once the project was run.
Will Combo Cleaner protect me from malware?
Yes, Combo Cleaner can detect and remove most known malware, including RATs. Advanced threats like NodeRabbit tend to hide deep in the system, so running a full system scan is recommended to make sure nothing is left behind.
Share:
Tomas Meskauskas
Expert security researcher, professional malware analyst
I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.
PCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
DonatePCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
Donate
▼ Show Discussion