Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Operation PCPcat Exploits Next.js and React, Impacting 59,000+ Servers

A credential-stealing campaign, "Operation PCPcat," has compromised over 59,000 Next.js servers globally. The campaign exploits critical vulnerabilities in the React framework, targeting sensitive authentication data.

A credential-stealing campaign, "Operation PCPcat," has compromised over 59,000 Next.js servers globally. The campaign exploits critical vulnerabilities in the React framework, targeting sensitive authentication data.

Researchers identified the operation through honeypot monitoring, accessing the attackers' command-and-control infrastructure. The campaign has a 64.6% exploitation success rate, leading to 59,128 confirmed server compromises and approximately 300,000 to 590,000 credentials stolen.

The attackers exploit two critical vulnerabilities, CVE-2025-29927 and CVE-2025-66478, for remote code execution in Next.js deployments. The attack chain involves mass scanning of Next.js domains, followed by prototype pollution attacks using JSON payload manipulation.

Malware executes data extraction routines targeting .env files, SSH keys, cloud credentials, and environment variables. The command-and-control infrastructure, located in Singapore, operates through four primary API endpoints for task assignments, data collection, and operational metrics.

A credential-stealing campaign, "Operation PCPcat," has compromised over 59,000 Next.js servers globally.
Eleanor Tate · Thehackingpost

The malware installs GOST proxy software and Fast Reverse Proxy components for persistence, enabling continuous scanning. Each compromised machine queries the C2 server for new targets every 45 minutes, potentially affecting 41,000 additional servers daily.

Organizations using Next.js should audit their deployments for unauthorized access, review .env file contents, rotate exposed credentials, and implement network segmentation. Detection can be enhanced using Suricata rules for prototype pollution attempts, YARA signatures for "pcpcat" malware, and behavioral analysis of child_process execution patterns.

67.217.57.240:666 - Distribution server (payload hosting) 67.217.57.240:888 - FRP C2 (reverse tunneling) 67.217.57.240:5656 - Main C2 API (task assignment, data exfiltration)

Advertisement

http://67.217.57.240:5656/domains - Target assignment (fetches 2000 IPs) http://67.217.57.240:5656/result - Data exfiltration (accepts credential POST) http://67.217.57.240:5656/health - Health check http://67.217.57.240:5656/stats - Operational metrics (EXPOSES CAMPAIGN DATA)

http://67.217.57.240:666/files/proxy.sh - Persistence installer http://67.217.57.240:666/files/react.py - Scanner/exploit module

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories