Fake 'interview' repos lure Next.js devs into running secret-stealing malware
ID: d66ea82b-ca7c-548a-bbe7-365e67878d93
STIX ID: report--d66ea82b-ca7c-548a-bbe7-365e67878d93
Feed Name: The Register (Security)
Microsoft reports a targeted campaign in which attackers publish malicious Next.js repositories that trigger during normal developer workflows (editor automation, npm run dev, backend initialization) to execute in-memory JavaScript loaders, connect to rotating C2 infrastructure, and retrieve follow-on tasks that can exfiltrate source code, secrets, and other sensitive developer-hosted assets. Defenders are advised to monitor unusual Node executions, unexpected outbound connections from developer machines, and follow-on discovery or upload behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
