Microsoft reported an ongoing social-engineering campaign targeting software developers with job-themed lures that direct victims to trojanized code repositories (including Next.js-branded projects and “technical assessment” materials). The repositories are designed to trigger remote code execution and then retrieve and execute attacker-controlled JavaScript that transitions into a staged backdoor with persistent command-and-control (C2), aligning with tradecraft previously associated with North Korea-linked fake recruitment activity.
Separately, researchers also disclosed a software supply-chain campaign involving malicious NuGet packages that targeted ASP.NET developers by stealing ASP.NET Identity data (e.g., user accounts, roles, and permission mappings) and modifying authorization logic to maintain access; one package acted as a dropper that installed a localhost proxy on 127.0.0.1:7152 to relay traffic to an external C2 resolved dynamically at runtime. Other items in the set are unrelated (e.g., generic industry commentary, venture funding news, and incident roundups) and do not add technical detail to the developer-focused repository backdoor campaign described by Microsoft.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft publicly reported a campaign using fake job interview and recruitment lures to deliver malicious Next.js repositories that can trigger remote code execution, staged command-and-control, and persistence on developer systems. The company said the tradecraft aligns with North Korean activity and warned of software supply-chain risk from compromised developer endpoints.
Using Microsoft Defender telemetry, investigators identified suspicious outbound connections from Node.js processes to attacker infrastructure and traced them to multiple Trojanized Next.js repositories with shared behavior.
Microsoft said the 2026 activity echoes earlier job-themed developer targeting historically associated with North Korea's Lazarus group, including 'Dream Jobs' style operations dating back to at least 2021.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.