MEDIUMVulnerability
Global

Hackers exploit React2Shell in automated credential theft campaign

Sunday, April 5, 2026 at 02:17 PM UTC·Source: BleepingComputer

Updated: Monday, April 6, 2026 at 12:17 AM UTC

Executive Summary

Hackers are running a large-scale campaign to steal credentials in an automated way after exploiting React2Shell (CVE-2025-55182) in vulnerable Next.js apps. [...]

Analysis

Hackers are running a large-scale campaign to steal credentials in an automated way after exploiting React2Shell (CVE-2025-55182) in vulnerable Next.js apps. [...]

Indicators of Compromise (1)

CVE (1)
CVE-2025-55182
Source Attribution

Originally published by BleepingComputer on Apr 5, 2026.

Related Threats