logo

Fake 'interview' repos lure Next.js devs into running secret-stealing malware

ID: d66ea82b-ca7c-548a-bbe7-365e67878d93

STIX ID: report--d66ea82b-ca7c-548a-bbe7-365e67878d93

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-02-25

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Microsoft reports a targeted campaign in which attackers publish malicious Next.js repositories that trigger during normal developer workflows (editor automation, npm run dev, backend initialization) to execute in-memory JavaScript loaders, connect to rotating C2 infrastructure, and retrieve follow-on tasks that can exfiltrate source code, secrets, and other sensitive developer-hosted assets. Defenders are advised to monitor unusual Node executions, unexpected outbound connections from developer machines, and follow-on discovery or upload behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.