logo

UAT-10608 Uses a Next.js “React2Shell” Flaw to Map Your Entire Cloud

ID: 5a20a3ae-57cb-593e-aeb6-2c1aec3948dc

STIX ID: report--5a20a3ae-57cb-593e-aeb6-2c1aec3948dc

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-04-07

Date Updated: 2026-04-23

Author: Ddos

...
...

Cisco Talos disclosed an active automated credential-harvesting campaign (UAT-10608) exploiting the React2Shell vulnerability (CVE-2025-55182) in Next.js applications to deploy a multi-stage harvester named "NEXUS Listener" that collects SSH keys, cloud tokens, environment and database credentials, and package registry tokens and exfiltrates them to a web-based C2 GUI; at least 766 hosts across multiple cloud providers have been compromised, enabling supply-chain attacks, targeted follow-on intrusions, and regulatory-impacting data exposures, and Talos recommends patching, strict secret management, and immediate rotation of potentially exposed credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.