The images in this article were generated with artificial intelligence. How we publish
A powerful automated operation is taking advantage of a vulnerability in Next.js applications to start a massive theft of credentials that, according to researchers, has already compromised hundreds of servers in the cloud. The exploited vector is known as React2Shell (CVE-2025-55182) and, once the attacker gets access, unfolds scripts that show and exfilter secrets, keys and credentials systematically.
The technical details and campaign follow-up have been documented by Cisco Talos analysts, who attribute the operation to a cluster of threats identified as UAT-10608. In their research the experts were able to access an exposed body of the control component called NEXUS Listar, which allowed them to observe live information that the intruders were collecting and how they presented it: an interface that groups and facilitates the search, filtering and statistics of the secrets removed. Talos report can be consulted to expand the findings and see panel catches: Cisco Talos - Inside a large-scale automated credential-harvesting operation.

The modus operandi described by the researchers starts with automated scans looking for vulnerable Next.js. After exploiting React2Shell, the attacker drops a script into a temporary directory that runs a multi-phase routine to extract sensitive secrets and files. This material is packed in fragments and sent by HTTP to the command and control server - the NEXUS Listar - typically through port 8080, where it is indexed and available for analysis by malicious operators.
The magnitude of the incident is striking: Talos reported that the operating infrastructure was able to compromise at least 766 hosts within 24 hours. Among the elements that the attackers collected are environment variables and application secrets (API keys, database credentials, GitHub / GitLab tokens), private SSH keys, cloud credentials (AWS / GCP / Azure's AMI metadata and credentials), Kubernetes tokens, container and Docker information, command histories and process data in progress.
The risk is not limited to the timely loss of secrets. With these elements an attacker can perform cloud account-taking, access to databases and payment systems, move laterally using SSH keys or launch supply chain attacks using persistent access. There is also a regulatory cost because exfiltration may include personal data subject to privacy regulations.
In the face of such campaigns, the recommendations of the response teams combine immediate and strategic action. As a matter of urgency, it is essential to apply the patches that close React2Shell and, in the light of the minimal suspicion of exposure, to rotate all the credentials concerned. Cisco Talos insists on the need to audit possible data exposures on the server and replace reused SSH keys. For cloud-level defense, it is recommended to force the use of IMDSv2 in AWS EC2 instances to make it difficult to obtain instance metadata from committed processes; the official AWS documentation explains how to configure and force IMDSv2: AWS - Configuring the Instance Metadata Service.
Other preventive measures include the adoption of secret scanning in repositories and pipelines (for example, solutions to secret scanning offering platforms such as GitHub), regular and automated rotation of credentials, strict application of the principle of lesser privilege in the roles and permissions of containers and cloud accounts, and implementation of application protections such as WAF or RASP to reduce the likelihood of operating failures in web applications. GitHub documents its secret detection capabilities in the code and in the history of the repository: GitHub - Secret scanning, and the OWASP secret management guide offers good storage and rotation practices: OWASP - Secrets Management Cheat Sheet.

In the operational plane, it is also appropriate to tighten detection and telemetry: to monitor outgoing HTTP connections to unusual ports (like 8080) from application servers, to review processes and files in / tmp in search of malicious scripts, to audit command histories and container configuration files, and to establish abnormal alerts for the use of keys and tokens. Limiting the output traffic to known destinations and forcing the discharge filtering reduces the ability of an intruder to exfiltrate data to C2 infrastructure.
This campaign puts two simple but critical ideas on the table again: first, that the vulnerabilities in the application layer remain an extremely lucrative gateway for the attackers; and second, that the protection of secrets and credentials must be both preventive and reactive. Apply patches quickly, audit the exposure of sensitive information and have automatic processes to rotate and detect filtered secrets are minimum steps that can now make the difference between a contained incident and a gap with far-reaching consequences.
To read the technical analysis and indicators shared by the researchers, see the Cisco Talos report: Inside a large-scale automated credential-harvesting operation. If you need practical guidance to audit your environment or prioritize mitigation, the AWS and OWASP guides linked above are good starting points.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...