Microsoft Threat Intelligence @threatintel.microsoft.com · Feb 24

Microsoft Defender Experts uncovered a coordinated campaign targeting developers through malicious repositories disguised as legitimate Next.js projects and technical assessments leading to command and control, payload delivery, and data exfiltration: msft.it/63327QZtTN

3 likes 1 replies

?

Replies

Microsoft Threat Intelligence · Feb 24

Multiple entry points lead to the same outcome: runtime retrieval and local execution of attacker-controlled JavaScript that then transitions into staged C2, enabling persistent tasking, in-memory execution, discovery, and other follow-on actions.