thehackernews.com 4/2/2026, 9:05:15 PM · via preferred

Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal Credentials

Attackers Exploit Next.js Bug, Loot Credentials From 766 Hosts

According to Talos, a threat actor tracked as UAT-10608 exploited vulnerable Next[.]js applications to compromise systems and exfiltrate credentials at scale, leveraging automated scanning to target Next[.]js deployments affected by CVE-2025-55182 (CVSS 10) a critical React vulnerability known as React2Shell. Following initial access, the operation used…

First seen 2026-03-06T10:27:52.535Z · Last seen 2026-04-03T11:21:47.666Z

CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available

ACCORDING to Cisco Talos, a large-scale credential harvesting operation has been observed exploiting the React2Shell vulnerability (CVE-2025-55182) as an initial infection vector to steal a range of credentials, including database credentials, SSH private keys, AWS secrets, Stripe API keys, and GitHub tokens, at scale. At least 766 Next[.]js hosts across multiple regions and cloud providers have been compromised as part of the activity.

Talos described the operation as automated, with post-compromise scripts that extract and exfiltrate credentials to a command-and-control host run by a web GUI named “NEXUS Listener,” which offers statistics on compromised hosts and harvested credentials. The campaign is targeting Next[.]js applications vulnerable to CVE-2025-55182, described as a critical flaw in React Server Components and Next[.]js App Router that could enable remote code execution for initial access.

The researchers, Asheer Malhotra and Brandon White, said the breadth of data collected includes environment variables, API keys, IAM credentials, and cloud service tokens, underscoring how compromised hosts could be used for follow-on attacks or re-sold access.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline