The repository already includes pre-built files in the build directory, so you can skip step 3 if you don't plan to modify the source code.
A developer-targeting campaign leveraged malicious Next.js repositories to trigger a covert RCE-to-C2 chain through standard ...