HomeSecurityMicrosoft: Hackers target developers with malicious Next.js repositories

Microsoft: Hackers target developers with malicious Next.js repositories

Microsoft has uncovered a coordinated campaign targeting software developers through malicious repositories, posing as legitimate Next.js projects and technical reviews . The campaign uses carefully crafted decoys to integrate into everyday workflows, such as cloning repositories, opening projects, and running builds, allowing the malicious code to run undetected.

Microsoft malicious Next.js repositories

Telemetry data, collected during an incident investigation by Microsoft, indicated the campaign's alignment with a broader set of threats that use work-themed tricks.

“ During the initial analysis of the incident, Defender telemetry revealed a limited set of malicious repositories that were directly involved in the observed breaches ,” the company wrote in a post. “ Further investigation revealed additional related repositories, which were not directly referenced in the observed logs, but exhibited the same execution mechanisms, loader logic, and staging infrastructure .”

See also: Fake Zoom meetings install surveillance software

The campaign exploits developers' trust in shared code and gains access to high-value developer systems that often contain source code, environment secrets, credentials, and access to build or cloud infrastructure.

Microsoft: Multiple triggers for remote control

Microsoft researchers found that the malicious repositories were designed to offer multiple execution paths, ultimately leading to the same backdoor behavior.

Microsoft: Hackers target developers with malicious Next.js repositories

In some cases, simply opening the project in Visual Studio Code was enough. Attackers exploited workspace automation by embedding tasks that are configured to run automatically when a folder is opened. This causes code to execute without the developer having to do anything.

Other variants rely on build processes or server startup routines, ensuring that malicious code is executed when developers perform typical actions such as starting a development server. Regardless of activation, repositories retrieve additional JavaScripts from remote infrastructure and execute them in memory, reducing the disk footprint.

The recovered payload operates in stages. An initial registration component identifies the computer and can deliver bootstrap instructions. Then, a separate C2 controller provides persistence and enables subsequent actions such as payload delivery and data extraction.

See also: Russian UAC-0050 targets European financial institution

Infection via a fake “coding test”

Microsoft said the investigation began by analyzing suspicious outbound connections from Node.js processes, which were communicating with attacker-controlled servers. Correlating network activity with process telemetry led analysts back to the initial infection through recruiting exercises.

One of the repositories was hosted on Bitbucket and presented as a technical review, along with a related repository that used the conventional name Cryptan-Platform-MVP1.

“Multiple repositories followed repeating naming conventions and project 'family' patterns, allowing targeted searches for additional related repositories, which did not directly refer to the observed telemetry, but exhibited the same execution and staging behavior,” Microsoft wrote.

See also: Russian group exploits weak Fortinet firewalls via AI

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Microsoft: Hackers target developers with malicious Next.js repositories

If an infection occurs, affected organizations should immediately mitigate suspect endpoints, trace the initial process tree , and look for repeated communication with suspect infrastructure. Because credential and session theft may follow, responders should assess identity risk, revoke sessions, and mitigate high-risk SaaS actions to limit exposure during the investigation.

Long-term mitigation actions include focusing on tightening developer trust boundaries and reducing execution risk. Other recommendations include enforcing Visual Studio Code Workspace Trust defaults, implementing attack surface reduction rules, enabling cloud-based reputation protections , and strengthening conditional access.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS