Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal Credentials
ID: 5f82512f-9e29-55dc-a6de-3956c40fb2a2
STIX ID: report--5f82512f-9e29-55dc-a6de-3956c40fb2a2
Feed Name: The Hacker News
A large-scale credential-harvesting campaign attributed to threat cluster UAT-10608 leverages the critical React2Shell vulnerability (CVE-2025-55182, CVSS 10.0) in Next.js to gain remote code execution, drop the NEXUS Listener collection framework, and exfiltrate database credentials, SSH private keys, cloud IMDS credentials, API keys (Stripe, OpenAI, etc.), Git tokens, and other secrets from at least 766 compromised hosts; the operation uses automated scanning to find vulnerable Next.js deployments and a password-protected web GUI to view and analyze stolen data, posing significant risk for follow-on attacks and lateral access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
