Over 59,000 servers running popular React frameworks like Next.js have been breached in just 48 hours as part of the widespread automated cyberespionage campaign Operation PCPcat, marking one of the fastest-moving attacks on modern web infrastructure, reports The Cyber Express.
The attackers are exploiting two critical, recently disclosed vulnerabilities, CVE-2025-29927 and CVE-2025-66478, using a technique called prototype pollution to achieve remote code execution and bypass authentication.
Once a server is breached, the deployed malware acts as a highly efficient credential stealer, harvesting hundreds of thousands of credentials from environment files, SSH keys, and cloud service accounts, posing a severe risk to connected infrastructure. The operation is coordinated via a centralized command-and-control server in Singapore and is designed to be self-sustaining, with each infected machine automatically scanning for thousands of new targets every 45 minutes.
Security researchers emphasize the need for immediate action, including patching vulnerabilities, rotating all exposed credentials, and monitoring for suspicious outbound traffic to known malicious infrastructure.
The attackers are exploiting two critical, recently disclosed vulnerabilities, CVE-2025-29927 and CVE-2025-66478, using a technique called prototype pollution to achieve remote code execution and bypass authentication.
Once a server is breached, the deployed malware acts as a highly efficient credential stealer, harvesting hundreds of thousands of credentials from environment files, SSH keys, and cloud service accounts, posing a severe risk to connected infrastructure. The operation is coordinated via a centralized command-and-control server in Singapore and is designed to be self-sustaining, with each infected machine automatically scanning for thousands of new targets every 45 minutes.
Security researchers emphasize the need for immediate action, including patching vulnerabilities, rotating all exposed credentials, and monitoring for suspicious outbound traffic to known malicious infrastructure.
