Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts Steal Credentials
In order to steal database credentials, SSH private keys, Amazon Web Services (AWS) secrets, shell command history, Stripe API keys, and GitHub tokens at scale, a large-scale credential harvesting operation has been detected using the React2Shell vulnerability as an initial infection vector.
The operation has been linked by Cisco Talos to a threat cluster known as UAT-10608. As part of the operation, at least 766 hosts from various cloud providers and geographical locations have been compromised.
In a report shared with The Hacker News prior to publication, security researchers Asheer Malhotra and Brandon White stated that UAT-10608 uses automated scripts to extract and exfiltrate credentials from a range of applications, which are then posted to its command-and-control (C2).
A w...








