Hackers exploit React2Shell in automated credential theft campaign
ID: c779e2eb-a614-50cb-8290-624195c660c4
STIX ID: report--c779e2eb-a614-50cb-8290-624195c660c4
Feed Name: Bleeping Computer
Cisco Talos reports a large-scale automated campaign exploiting React2Shell (CVE-2025-55182) in Next.js apps using a framework called NEXUS Listener; at least 766 hosts were compromised within 24 hours to harvest and exfiltrate environment variables, SSH keys, cloud credentials, Kubernetes tokens, and other secrets, enabling potential cloud account takeover, lateral movement, and supply-chain risks. Recommended mitigations include applying patches, rotating credentials, enforcing IMDSv2, enabling secret scanning, and deploying WAF/RASP and least-privilege controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
