Fake Next.js job interview tests backdoor developer's devices
ID: 6bf69dd1-b880-50be-bf47-6ba4e8c6d089
STIX ID: report--6bf69dd1-b880-50be-bf47-6ba4e8c6d089
Feed Name: Bleeping Computer
Microsoft Defender reported a coordinated campaign targeting software developers by publishing malicious Next.js repositories and coding-assessment lures; when cloned or opened, these projects trigger JavaScript loaders (via VS Code workspace tasks, dev server assets, or backend startup logic) that fetch and execute in-memory backdoors providing remote code execution, C2-based tasking, file enumeration, and staged exfiltration. Multiple repositories sharing naming, loader structure, and staging infrastructure indicate a sustained, organized effort; recommended mitigations include enforcing VS Code Workspace Trust/Restricted Mode, applying ASR rules, minimizing stored secrets, and using short-lived tokens.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
