New from Microsoft Threat Intelligence: Developer-targeting campaign using malicious Next.js repositories https://www.microsoft.com/en-us/security/blog/2026/02/24/c2-developer-targeting-campaign/

Developer-targeting campaign using malicious Next.js repositories | Microsoft Security Blog
A developer-targeting campaign leveraged malicious Next.js repositories to trigger a covert RCE-to-C2 chain through standard build workflows. The activity demonstrates how staged command-and-control can hide inside routine development tasks.