Skip to content
Malicious Repositories Target Next.js Developers with Covert RCE Attacks

Malicious Repositories Target Next.js Developers with Covert RCE Attacks

First seen 25 Feb 2026, 17:12 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

Hackers are targeting JavaScript developers by seeding malicious repositories that appear legitimate. Microsoft reported that these repositories exploit standard build workflows to execute malicious JavaScript in memory, leading to remote code execution and command-and-control activities. The campaign specifically affects developers working with Next.js frameworks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 183d ago How this analysis works

Timeline

2026-02-24
Microsoft reports on malicious .js repositories targeting developers
2026-02-25
The Register publishes article on the same malicious campaign

More articles in this cluster (10)

Following this threat?

Track Vercel in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed