logo

Developer-targeting campaign using malicious Next.js repositories

ID: 169dd427-032b-50c4-9a06-e73fb3b440c7

STIX ID: report--169dd427-032b-50c4-9a06-e73fb3b440c7

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2026-02-24

Date Updated: 2026-04-28

Author: Microsoft Defender Experts and Microsoft Defender Security Research Team

...
...

Microsoft Defender details a coordinated developer-targeting campaign that uses recruiting-themed and Next.js repositories to trigger runtime retrieval and in-memory execution of attacker-controlled JavaScript. The report describes three execution paths (VS Code workspace tasks, trojanized dev-server assets, and backend startup that exfiltrates environment variables), a two-stage C2 (Stage 1 registrar and Stage 2 tasking controller), telemetry and IoCs (Vercel domains, IPs, URLs, filepaths, and file hashes), hunting queries, and actionable mitigation guidance to protect developer workflows and credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.