216.73.216.233

Developer-targeting campaign using malicious Next.js repositories

· Published 24/02/2026 21:29 · Modified 24/02/2026 21:54

Export JSON

Essential information

Published
24/02/2026 21:29
Modified
24/02/2026 21:54
Tags
2026-02-24 command and control developer-targeting environment variable exfiltration javascript next.js node.js remote code execution visual studio code
Related entities
4 observables, 18 techniques (mitre), 1 others

Description

A coordinated campaign is targeting developers through malicious repositories disguised as legitimate projects and technical assessment materials. The attack uses multiple entry points that lead to runtime retrieval and local execution of attacker-controlled , transitioning into staged command-and-control. The campaign employs three main execution paths: workspace automation, build-time execution during application development, and server startup execution via and dynamic . The attack chain includes a Stage 1 C2 beacon for registration and a Stage 2 C2 controller for persistent tasking. This sophisticated approach allows attackers to blend into routine developer workflows, increasing the likelihood of code execution and potentially compromising high-value assets such as source code, environment secrets, and access to build or cloud resources.

External references