Next.js React2Shell Exploit Automates AI and Cloud Credential Theft
React2Shell exploitation has escalated from remote code execution to automated mass credential harvesting on vulnerable Next.js React Server Components. Attackers now extract AI API keys, cloud tokens, SSH keys, and environment secrets from at least 766 compromised servers worldwide without further interaction after initial exploitation. This turns each infected host into a gateway for deeper access to cloud platforms, AI services, and SSH targets, extending the blast radius beyond the web application itself. Patch vulnerable React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 immediately. Treat all secrets accessible from affected hosts as compromised, as remediation of the host alone does not prevent follow-on attacks using stolen credentials.