logo

Attackers Abuse React2Shell Flaw to Compromise 700+ Next.js Hosts

ID: 9375784e-9957-5e3b-83d9-437a9cb36c22

STIX ID: report--9375784e-9957-5e3b-83d9-437a9cb36c22

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-04-03

Date Updated: 2026-04-22

Author: Divya

...
...

An active automated campaign (UAT-10608) is exploiting CVE-2025-55182 in React Server Components to execute arbitrary code on public Next.js applications, compromising at least 766 hosts in 24 hours. The attackers deploy a multi-stage harvesting script that enumerates environment variables, cloud metadata, Kubernetes tokens, shell histories, running containers, and exfiltrates database credentials, SSH keys, payment and API tokens to a web-based C2 named "NEXUS Listener"; immediate patching and rotation of exposed credentials is strongly advised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.