Microsoft Warns Developers of Fake Next.js Job Repos Delivering In-Memory Malware
ID: 3d7d8e0b-cb29-5136-9379-dbe6bdb70d7a
STIX ID: report--3d7d8e0b-cb29-5136-9379-dbe6bdb70d7a
Feed Name: The Hacker News
A coordinated developer‑targeting campaign uses fake repositories, malicious VS Code tasks, modified JavaScript libraries, and runtime retrieval of attacker-controlled JavaScript (hosted on Vercel, GitHub gists, Google Drive, and other services) to achieve in-memory Node.js execution, profile hosts, exfiltrate environment data, obtain an instanceId for tracking, and deploy a second-stage controller that provides persistent C2 and data‑stealing capabilities; Microsoft, GitLab, Abstract Security, Red Asgard, and others associate these tactics with a North Korea‑linked cluster (Contagious Interview).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
