HomeSecurityHackers Exploit CVE-2025-55182 to Compromise 766 Next.js Hosts

Hackers Exploit CVE-2025-55182 to Compromise 766 Next.js Hosts

A large-scale credential harvesting operation targeting Next.js Hosts has been observed exploiting the React2Shell as an initial point of infection to steal database credentials, SSH private keys, Amazon Web Services (AWS) secrets, shell command history, Stripe API keys, and GitHub tokens on a large scale. Cisco Talos has attributed the operation to a threat group it tracks as UAT-10608.

See also: Stryker returns to full operation after data-wiping attack

Next.js Hosts
Hackers Exploit CVE-2025-55182 to Compromise 766 Next.js Hosts

At least 766 hosts spanning multiple geographies and cloud providers have been compromised as part of the activity. “After the breach, UAT-10608 leverages automated scripts to extract credentials from various applications, which are then posted to its command-and-control (C2),” security researchers Asheer Malhotra and Brandon White in a report shared with The Hacker News ahead of publication.

“The C2 hosts a graphical user interface (GUI) titled ‘NEXUS Listener’ that can be used to view the stolen information and obtain analytical insights using pre-aggregated statistics on the credentials collected and the hosts compromised.” The campaign is estimated to target Next.js applications that are vulnerable to CVE-2025-55182 (CVSS score: 10.0), a critical vulnerability in React Server Components and Next.js App Router that could lead to remote code execution, for initial access and then install the NEXUS Listener collection framework.

See also: What the Kash Patel email breach really means

Hackers Exploit CVE-2025-55182 to Compromise 766 Next.js Hosts
Hackers Exploit CVE-2025-55182 to Compromise 766 Next.js Hosts

This is achieved through a dropper that proceeds to deploy a multi-phase collection script that collects various details from the compromised system:

  • Environment variables
  • JSON environment from JS runtime
  • SSH private keys and authorized_keys
  • Shell command history
  • Kubernetes service account tokens
  • Docker container configurations (current containers, their images, exposed ports, network configurations, mount points, and environment variables)
  • Temporary IAM credentials associated with roles via queries to the Instance Metadata Service for AWS, Google Cloud, and Microsoft Azure

The cybersecurity firm said the scope of the victim pool and indiscriminate targeting pattern align with automated scans, likely leveraging services like Shodan, Censys, or custom scanners, to identify publicly accessible Next.js Hosts and scan them for the vulnerability.

Central to the framework is a password-protected web application that makes all stolen data available to the operator through a graphical user interface that has search capabilities to search for the information.

The current version of NEXUS Listener is V3, indicating that the tool has undergone significant development before reaching its current stage. Talos, which managed to obtain data from an uncertified NEXUS Listener instance, said it contained API keys related to Stripe, AI platforms (OpenAI, Anthropic, and NVIDIA NIM), communication services (SendGrid and Brevo), along with Telegram bot tokens, webhook secrets, GitHub and GitLab tokens, database connection strings, and other application secrets.

See also: Intesa Sanpaolo: Fine for previous data leak

Hackers Exploit CVE-2025-55182 to Compromise 766 Next.js Hosts
Hackers Exploit CVE-2025-55182 to Compromise 766 Next.js Hosts

The extensive data collection operation highlights how malicious actors could leverage access to compromised Next.js Hosts to orchestrate subsequent attacks. Organizations are urged to review their environments to implement the principle of least privilege, enable secret scanning, avoid reusing SSH key pairs, implement IMDSv2 enforcement on all AWS EC2 instances, and rotate credentials if they suspect a breach.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS