Hackers Compromised 700+ Next.js Hosts by Exploiting React2Shell Vulnerability
ID: ca284a81-95a9-50f5-8586-3fb43aa0d6e5
STIX ID: report--ca284a81-95a9-50f5-8586-3fb43aa0d6e5
Feed Name: cybersecurityNews.com
Threat Score
Cisco Talos researchers uncovered an active mass credential-theft campaign by group UAT-10608 exploiting a critical React Server Components RCE (CVE-2025-55182, aka React2Shell) in Next.js servers; automated scanners deployed an infostealer that harvested DB credentials, SSH keys, cloud tokens, payment keys and GitHub tokens from 700+ hosts and reported them to a 'NEXUS Listener' dashboard, enabling large-scale account and cloud takeovers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
