Malicious Next.js Repos Target Developers Via Fake Job Interviews
ID: 7fd6ec3f-1cb5-503d-b20a-5346224895ba
STIX ID: report--7fd6ec3f-1cb5-503d-b20a-5346224895ba
Feed Name: Dark Reading
Threat Score
Microsoft researchers uncovered a developer‑targeting campaign that weaponizes malicious Next.js repositories and fake recruitment/interview materials to achieve remote code execution and establish persistent C2 on compromised developer hosts; attackers abused VS Code workspace automation and obfuscated assets to fetch and execute attacker-controlled JavaScript, risking exposure of source code, secrets, build and cloud access and enabling supply‑chain compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
