As detailed in The Hacker News, a significant credential harvesting operation has been identified, leveraging the React2Shell vulnerability as its primary entry point to steal sensitive data at scale. This operation targets database credentials, SSH keys, AWS secrets, and other critical information.The threat cluster, identified as UAT-10608 by Cisco Talos, has compromised at least 766 hosts across various regions and cloud providers. The attackers exploit CVE-2025-55182, a critical flaw in Next.js applications, to gain initial access. Once inside, automated scripts extract environment variables, SSH keys, shell history, Kubernetes tokens, Docker configurations, API keys, cloud provider credentials, and running processes. This stolen data is exfiltrated to a command-and-control server hosting a web interface called "NEXUS Listener," which provides operators with a GUI to view and analyze the harvested information, including statistics on compromised hosts and credential types.Organizations are urged to implement the principle of least privilege, enable secret scanning, avoid SSH key reuse, enforce IMDSv2 on AWS, and rotate credentials if compromise is suspected. The aggregated data provides attackers with a detailed map of victim infrastructure, valuable for targeted follow-on attacks, social engineering, or resale to other threat actors.Source: The Hacker News
Threat Intelligence, Vulnerability Management, Patch/Configuration Management, Identity

Large-scale credential harvesting operation exploits React2Shell vulnerability
(Adobe Stock)

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
