Attackers Abuse React2Shell Flaw to Compromise 700+ Next.js Hosts
ID: 9375784e-9957-5e3b-83d9-437a9cb36c22
STIX ID: report--9375784e-9957-5e3b-83d9-437a9cb36c22
Feed Name: GBHackers
An active automated campaign (UAT-10608) is exploiting CVE-2025-55182 in React Server Components to execute arbitrary code on public Next.js applications, compromising at least 766 hosts in 24 hours. The attackers deploy a multi-stage harvesting script that enumerates environment variables, cloud metadata, Kubernetes tokens, shell histories, running containers, and exfiltrates database credentials, SSH keys, payment and API tokens to a web-based C2 named "NEXUS Listener"; immediate patching and rotation of exposed credentials is strongly advised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
