Operation PCPcat Hacked 59,000+ Next.js/React Servers Within 48 Hours
ID: 39f98591-5156-5a9c-bf7b-10e47e7990a9
STIX ID: report--39f98591-5156-5a9c-bf7b-10e47e7990a9
Feed Name: cybersecurityNews.com
A widespread credential-theft campaign dubbed PCPcat exploited critical Next.js RCE vulnerabilities (CVE-2025-29927, CVE-2025-66478), compromising 59,128 of 91,505 scanned servers in under 48 hours. Attackers used prototype-pollution JSON payloads to execute commands, extracted .env files, SSH keys, AWS/Docker/Git credentials and bash history, and deployed SOCKS5 proxies, FRP tunnels and persistent systemd services for pivoting to a C2 at 67.217.57.240; the report provides IoCs, Suricata/YARA detection suggestions, and mitigation steps including patching, key rotation and blocking C2 domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
