logo

Microsoft Warns Developers of Fake Next.js Job Repos Delivering In-Memory Malware

ID: 3d7d8e0b-cb29-5136-9379-dbe6bdb70d7a

STIX ID: report--3d7d8e0b-cb29-5136-9379-dbe6bdb70d7a

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-02-26

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A coordinated developer‑targeting campaign uses fake repositories, malicious VS Code tasks, modified JavaScript libraries, and runtime retrieval of attacker-controlled JavaScript (hosted on Vercel, GitHub gists, Google Drive, and other services) to achieve in-memory Node.js execution, profile hosts, exfiltrate environment data, obtain an instanceId for tracking, and deploy a second-stage controller that provides persistent C2 and data‑stealing capabilities; Microsoft, GitLab, Abstract Security, Red Asgard, and others associate these tactics with a North Korea‑linked cluster (Contagious Interview).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.