The Interview Trap: Malicious Next.js Repositories Weaponize Coding Tests to Hack Developers
ID: 55ec62ad-422f-55a0-a56d-34f2fa826b5b
STIX ID: report--55ec62ad-422f-55a0-a56d-34f2fa826b5b
Feed Name: securityonline.info
Microsoft Defender Experts identified a coordinated campaign that lures software engineers with malicious Next.js projects and technical assessment materials. Attackers hide execution triggers in VS Code workspace tasks, trojanize JavaScript libraries to run at build time, and exfiltrate process environment variables at server startup. The operation uses a two-stage model: an initial bootstrap that profiles the host and establishes a durable identity, followed by an in-memory tasking client that enables directory discovery and staged uploads. The campaign targets developer workflows to access high-value assets (source code, secrets, build/cloud credentials), so defenders should monitor unusual Node activity, unexpected outbound connections, and developer-hosted discovery or upload behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
