Security Incident Report: Cryptominer Attack on Next.js Application
dev.to·2d·
Discuss: DEV
🦭Podman
Preview
Report Post

Introduction

On December 7-8, 2025, my Next.js portfolio application luisfaria.dev running on a DigitalOcean Ubuntu droplet was compromised by an automated cryptomining attack. The attacker successfully executed remote code on the containerized Next.js application, deploying cryptocurrency miners that ran for several hours before detection.

This document serves as a post-mortem analysis and educational resource for understanding how the attack occurred, what was compromised, and how to prevent similar incidents.

Timeline:

  • Attack Started: ~December 7, 21:52 UTC
  • Detection: December 8, ~18:00 UTC (via unusual container behavior)
  • Remediation: December 9, 2025 (full rebuild and investigation)
  • Posting: December 10, 2025 (this…

Similar Posts

Loading similar posts...