A large-scale credential theft campaign, identified as PCPcat, compromised over 59,000 publicly exposed Next.js servers within a 48-hour period. Attackers exploited critical remote code execution vulnerabilities, specifically CVE-2025-29927 and CVE-2025-66478, using a custom malware (react.py) to scan and infiltrate targets. Once access was gained, the attackers extracted sensitive credentials from .env files, SSH keys, AWS configurations, Docker tokens, and Git credentials, and established persistent access through the installation of proxy and tunneling tools such as GOST SOCKS5 and FRP. The campaign's command-and-control infrastructure was exposed, revealing operational statistics and methods for target assignment, data exfiltration, and health checks, with key indicators of compromise including specific IP addresses, files, processes, and log artifacts.
The operation was attributed to the group "PCP Cat," with evidence of their activity and communication channels found on Telegram. Security researchers provided detection rules for Suricata and YARA to identify malicious activity related to this campaign. The scale and speed of the attack, affecting over 59,000 servers in less than two days, highlight the critical need for organizations using Next.js to patch vulnerable systems and monitor for signs of compromise, especially given the attackers' use of prototype pollution and Docker API abuse for persistence and lateral movement.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
By 2025-12-24, reporting said the campaign's command-and-control infrastructure had been exposed, revealing operational details, indicators of compromise, and attribution to the 'PCP Cat' group. Researchers also published recommended mitigations including urgent patching, key rotation, C2 blocking, and monitoring, along with Suricata and YARA detection rules.
After compromising servers, the operators used react.py malware to steal sensitive credentials and install persistent proxy and tunneling services on affected systems. Reporting indicated the exposed infrastructure suggested a very high compromise rate and projected more than 300,000 credentials could be harvested.
Within a 48-hour period ending around 2025-12-24, attackers in the PCPcat campaign compromised roughly 59,000 to 60,000 internet-exposed Next.js/React servers. The operation reportedly exploited CVE-2025-29927 and CVE-2025-66478 to gain remote code execution at scale.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.