logo

Automated Credential Harvesting Campaign Exploits React2Shell Flaw

ID: 84d84fc8-295f-5374-9da6-5afc9c7c7576

STIX ID: report--84d84fc8-295f-5374-9da6-5afc9c7c7576

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-04-06

Date Updated: 2026-04-22

Author: Elizabeth Montalbano

...
...

Cisco Talos identified a global automated campaign (attributed to UAT-10608) exploiting the React2Shell pre-auth RCE (CVE-2025-55182) in Next.js Server Components to deploy the NEXUS Listener credential-harvesting framework, resulting in at least 766 compromised hosts and large-scale exfiltration of SSH keys, cloud tokens, and environment secrets; mitigations include patching, credential rotation, least-privilege enforcement, metadata access restriction, secrets scanning, and monitoring for specific forensic artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.