Hackers exploit React2Shell in automated credential theft campaign

Hackers are running a large-scale campaign to steal credentials in an automated way after exploiting React2Shell (CVE-2025-55182) in vulnerable Next.js apps.

BleepingComputer
@thenewoil The automation aspect is particularly concerning here. Once attackers weaponize a new technique like React2Shell, the speed of exploitation across vulnerable targets increases dramatically. Wonder how many orgs are even aware they have exposed React applications that could be affected.