TGTGInsighttelegram intelligenceLIVE / telegram public index
← The Hacker News
The Hacker News avatar

TGINSIGHT POST

Post #8492

@thehackernews

The Hacker News

Views9,770Post view count
PostedFeb 2602/26/2026, 10:38 AM
Post content

Post content

⚠️ Microsoft says fake Next.js job repos are being used to gain persistent access to developer machines. Opening a VS Code project or running npm run dev can trigger hidden loaders that pull JavaScript into memory, profile the host, and connect to C2. GitLab banned 131 linked accounts and tracked heavy abuse of Vercel. 🔗 Read → https://thehackernews.com/2026/02/fake-nextjs-repos-target-developers.html