In order to steal database credentials, SSH private keys, Amazon Web Services (AWS) secrets, shell command history, Stripe API keys, and GitHub tokens at scale, a large-scale credential harvesting operation has been detected using the React2Shell vulnerability as an initial infection vector.
The operation has been linked by Cisco Talos to a threat cluster known as UAT-10608. As part of the operation, at least 766 hosts from various cloud providers and geographical locations have been compromised.
In a report shared with The Hacker News prior to publication, security researchers Asheer Malhotra and Brandon White stated that UAT-10608 uses automated scripts to extract and exfiltrate credentials from a range of applications, which are then posted to its command-and-control (C2).
A web-based graphical user interface (GUI) called “NEXUS Listener” is hosted by the C2 and may be used to see stolen data and provide analytical insights using precompiled statistics on hacked sites and credentials read more about Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts Steal Credentials.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
