security: Developer-targeting campaign using malicious Next.js repositories
Microsoft Security Blog
2026-02-24
Microsoft reports a developer-targeting campaign that used malicious Next.js repositories to achieve covert remote code execution and stage command-and-control via normal build workflows.