{"id":11829,"date":"2026-04-03T10:04:13","date_gmt":"2026-04-03T10:04:13","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/03\/hackers-compromised-700-next-js-hosts-by-exploiting-react2shell-vulnerability\/"},"modified":"2026-04-03T10:04:13","modified_gmt":"2026-04-03T10:04:13","slug":"hackers-compromised-700-next-js-hosts-by-exploiting-react2shell-vulnerability","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/03\/hackers-compromised-700-next-js-hosts-by-exploiting-react2shell-vulnerability\/","title":{"rendered":"Hackers Compromised 700+ Next.js Hosts by Exploiting React2Shell Vulnerability"},"content":{"rendered":"<p>    Hackers Compromised 700+ Next.js Hosts by Exploiting React2Shell Vulnerability<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A massive automated credential theft campaign is actively targeting web applications worldwide. Cybersecurity researchers at Cisco Talos have uncovered an operation by a hacker group tracked as UAT-10608, which has already compromised over 700 servers.<\/p>\n<p>The attackers are exploiting a critical security flaw known as React2Shell to gain access and steal highly sensitive data. The hackers are specifically targeting Next.js applications vulnerable to <a href=\"https:\/\/cybersecuritynews.com\/poc-exploit-react-next-js\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-55182, widely known as React2Shell<\/a>.<\/p>\n<p>This is a severe remote code execution flaw in React Server Components. It allows attackers to send a specially crafted web request to a vulnerable server.<\/p>\n<p>Because the server does not properly check the incoming data, it executes the attacker\u2019s hidden commands. Worst of all, this attack requires no passwords or user interaction.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-700-next-js-hosts-exploited\"><strong>700+ Next.js Hosts Exploited<\/strong><\/h2>\n<p>The UAT-10608 group uses automated tools to scan the internet for vulnerable Next.js servers. Once they find a target, they launch the <a href=\"https:\/\/cybersecuritynews.com\/attackers-exploiting-react2shell-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">React2Shell exploit to gain initial access<\/a>. The exploit then downloads a malicious script onto the server.<\/p>\n<p>This script runs quietly in the background, acting like a digital vacuum cleaner. It searches the server\u2019s files, cloud settings, and system memory to harvest valuable credentials.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhINmOtKf5IEAr4vZqtzNmSs8WR3DgMtt7SGieNHj7G4fOQzK3CSKwRMUvCeAzw29Ub4I3gtVGESD58S2y9sWMGf48Hu1VQSiSCo_Xg4GnwK_qZ8JlK82WRkZ1Lc_7Cx0tYKIe8pw9jy88exc5DbylTlHhUps7A5o9iGvqliiqSZDVcG0hsp_vYGBNwm4M\/s1600\/Screenshot%25202026-04-03%2520105838%2520%25281%2529.webp?ssl=1\" alt=\"NEXUS Listener Login Prompt(source : Cisco Talos )\"><figcaption class=\"wp-element-caption\"><em><em>NEXUS Listener Login Prompt<\/em><\/em>(source : Cisco Talos )<\/figcaption><\/figure>\n<\/div>\n<p>The script works in multiple phases, extracting everything from cloud tokens to database passwords, and then <a href=\"https:\/\/cybersecuritynews.com\/shelby-malware-steal-data-abusing-github\/\" target=\"_blank\" rel=\"noreferrer noopener\">sends the stolen data back to the hackers\u2019 command-and-control server.<\/a><\/p>\n<p>To manage the massive amount of stolen information, the attackers use a custom web dashboard called the \u201cNEXUS Listener\u201d. <a href=\"https:\/\/blog.talosintelligence.com\/uat-10608-inside-a-large-scale-automated-credential-harvesting-operation-targeting-web-applications\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Cisco Talos researchers discovered<\/a> that in just 24 hours, the dashboard recorded 766 compromised hosts.<\/p>\n<p>The dashboard revealed the shocking scale of the theft:<\/p>\n<ul class=\"wp-block-list\">\n<li>Over 90% of the hosts had their database credentials stolen.<\/li>\n<li>Nearly 80% <a href=\"https:\/\/cybersecuritynews.com\/ssh-keys\/\" target=\"_blank\" rel=\"noreferrer noopener\">lost their private SSH keys<\/a>, which are used to access servers securely.<\/li>\n<li>Hackers also stole AWS cloud credentials, live Stripe payment keys, and GitHub access tokens.<\/li>\n<\/ul>\n<p>The consequences of this attack are devastating. With the stolen database passwords, hackers can access private user information and financial records.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjjh6DTLek6PFsZdLgNwojhCJBnxoTk65jtwwlX2IDU1ijYlBUKptlfSg1gZ50Gh96CmtvCOMp3H3_d5zjorG44mE0UpSuNaePkaglOF_QZHGF44SxDK2WYzhQ4FljTw3MkCxL4zw2I4jD-a9pHOZDhK-BOiAfdhJwxW0zzpRInYxuCJVbyauiMu7OtphA\/s1600\/Screenshot%25202026-04-03%2520104535%2520%25281%2529.webp?ssl=1\" alt=\"NEXUS Listener victims list(source : Cisco Talos )\"><figcaption class=\"wp-element-caption\"><em><em>NEXUS Listener victims list<\/em><\/em> (source: Cisco Talos )<\/figcaption><\/figure>\n<p>The exposed SSH keys allow them to move freely across different servers within a company\u2019s network.<\/p>\n<p>Furthermore, stolen cloud credentials give attackers the power to take over entire cloud environments, <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">while<a href=\"https:\/\/cybersecuritynews.com\/shai-hulud-2-0-malware-attack-compromised-30000-repositories\/\" target=\"_blank\" rel=\"noopener\">\u00a0compromised<\/a><\/span><a href=\"https:\/\/cybersecuritynews.com\/shai-hulud-2-0-malware-attack-compromised-30000-repositories\/\" target=\"_blank\" rel=\"noreferrer noopener\"> GitHub tokens <\/a>could be used to insert malicious code into legitimate software updates.<\/p>\n<p>Companies using Next.js must take immediate action to protect themselves. Organizations should urgently update their <a href=\"https:\/\/cybersecuritynews.com\/2-15m-web-services-running-next-js-exposed\/\" target=\"_blank\" rel=\"noreferrer noopener\">web applications to patch the React2Shell vulnerability.<\/a><\/p>\n<p>Additionally, any company that might have been targeted should immediately change all its passwords, <a href=\"https:\/\/cybersecuritynews.com\/claude-code-hacked\/\" target=\"_blank\" rel=\"noreferrer noopener\">API keys, and security tokens<\/a>.<\/p>\n<p>Experts also recommend restricting access to cloud metadata services and carefully monitoring servers for any unusual background processes.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/700-next-js-hosts-exploited\/\">Hackers Compromised 700+ Next.js Hosts by Exploiting React2Shell Vulnerability<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/700-next-js-hosts-exploited\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Compromised 700+ Next.js Hosts by Exploiting React2Shell Vulnerability A massive automated credential theft campaign is actively targeting web applications worldwide. Cybersecurity researchers at Cisco Talos have uncovered an operation by a hacker group tracked as UAT-10608, which has already compromised over 700 servers. The attackers are exploiting a critical security flaw known as React2Shell [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-11829","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11829"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11829"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11829\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11829"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11829"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11829"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}