logo

UAT-10608: Inside a large-scale automated credential harvesting operation targeting web applications

ID: 5c8450ed-2787-561d-8021-0fbd514ceac6

STIX ID: report--5c8450ed-2787-561d-8021-0fbd514ceac6

Feed Name: Cisco Talos

Threat Score
80/100

Date Published: 2026-04-02

Date Updated: 2026-04-27

Author: Asheer Malhotra

...
...

Cisco Talos discloses an active, automated credential-harvesting campaign (UAT-10608) that leverages a pre-auth remote code execution vulnerability in React Server Components (React2Shell, CVE-2025-55182) against Next.js applications to deploy scripts that exfiltrate environment secrets, SSH private keys, cloud tokens, and API keys to a web-based C2 called NEXUS Listener; Talos observed at least 766 compromised hosts, exposed high-value credentials (AWS, Stripe, GitHub, SSH), provides IOCs, and issues remediation and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.