logo

Fake Next.js job interview tests backdoor developer's devices

ID: 6bf69dd1-b880-50be-bf47-6ba4e8c6d089

STIX ID: report--6bf69dd1-b880-50be-bf47-6ba4e8c6d089

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-02-25

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Microsoft Defender reported a coordinated campaign targeting software developers by publishing malicious Next.js repositories and coding-assessment lures; when cloned or opened, these projects trigger JavaScript loaders (via VS Code workspace tasks, dev server assets, or backend startup logic) that fetch and execute in-memory backdoors providing remote code execution, C2-based tasking, file enumeration, and staged exfiltration. Multiple repositories sharing naming, loader structure, and staging infrastructure indicate a sustained, organized effort; recommended mitigations include enforcing VS Code Workspace Trust/Restricted Mode, applying ASR rules, minimizing stored secrets, and using short-lived tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.