logo

Malicious Next.js Repos Target Developers Via Fake Job Interviews

ID: 7fd6ec3f-1cb5-503d-b20a-5346224895ba

STIX ID: report--7fd6ec3f-1cb5-503d-b20a-5346224895ba

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2026-02-25

Date Updated: 2026-04-21

Author: Elizabeth Montalbano

...
...

Microsoft researchers uncovered a developer‑targeting campaign that weaponizes malicious Next.js repositories and fake recruitment/interview materials to achieve remote code execution and establish persistent C2 on compromised developer hosts; attackers abused VS Code workspace automation and obfuscated assets to fetch and execute attacker-controlled JavaScript, risking exposure of source code, secrets, build and cloud access and enabling supply‑chain compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.