Mark RadarMARK RADAR
EN
Event File FINTECH Stripe

Hackers Exploit React2Shell at Scale to Harvest Stripe and Other Credentials

1 reports · First detected 2026-04-07 · Last active 2026-04-07

React2Shell (CVE-2025-55182) is a critical vulnerability disclosed in 2025 that affects web applications built with React and Next.js. Servers often store credentials for cloud services, deployment pipelines and Stripe payment interfaces. Exploitation of the flaw could therefore put corporate systems and transaction data at further risk.

The UAT-10608 hacking group has recently launched large-scale automated attacks to scan for and compromise Next.js hosts vulnerable to React2Shell. Hundreds of hosts worldwide have been affected, with attackers primarily harvesting SSH keys, cloud credentials and Stripe API keys. Reports have not disclosed the amount of financial losses or the exact dates of the attacks.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR