Hackers Exploit React2Shell at Scale to Harvest Stripe and Other Credentials
React2Shell (CVE-2025-55182) is a critical vulnerability disclosed in 2025 that affects web applications built with React and Next.js. Servers often store credentials for cloud services, deployment pipelines and Stripe payment interfaces. Exploitation of the flaw could therefore put corporate systems and transaction data at further risk.
The UAT-10608 hacking group has recently launched large-scale automated attacks to scan for and compromise Next.js hosts vulnerable to React2Shell. Hundreds of hosts worldwide have been affected, with attackers primarily harvesting SSH keys, cloud credentials and Stripe API keys. Reports have not disclosed the amount of financial losses or the exact dates of the attacks.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.