Malicious Repositories Target Next.js Developers with Covert RCE Attacks

Malicious Repositories Target Next.js Developers with Covert RCE Attacks

First seen 25 Feb 2026, 17:12 UTC Blogs.MicrosoftGbhackersCybersecuritynewsCyberpressDarkreading+4 83% similarity 26.3

Article Content

Browse articles
ThreatCluster

Hackers are targeting JavaScript developers by seeding malicious repositories that appear legitimate. Microsoft reported that these repositories exploit standard build workflows to execute malicious JavaScript in memory, leading to remote code execution and command-and-control activities. The campaign specifically affects developers working with Next.js frameworks.

ThreatCluster AI

Timeline

2026-02-24
Microsoft reports on malicious .js repositories targeting developers
2026-02-25
The Register publishes article on the same malicious campaign

Community

Browse all →