Developer-targeting campaign using malicious Next.js repositories
ID: 169dd427-032b-50c4-9a06-e73fb3b440c7
STIX ID: report--169dd427-032b-50c4-9a06-e73fb3b440c7
Feed Name: Microsoft Security
Date Published: 2026-02-24
Date Updated: 2026-04-28
Author: Microsoft Defender Experts and Microsoft Defender Security Research Team
Microsoft Defender details a coordinated developer-targeting campaign that uses recruiting-themed and Next.js repositories to trigger runtime retrieval and in-memory execution of attacker-controlled JavaScript. The report describes three execution paths (VS Code workspace tasks, trojanized dev-server assets, and backend startup that exfiltrates environment variables), a two-stage C2 (Stage 1 registrar and Stage 2 tasking controller), telemetry and IoCs (Vercel domains, IPs, URLs, filepaths, and file hashes), hunting queries, and actionable mitigation guidance to protect developer workflows and credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
