Operation PCPcat: Hunting a Next.js Credential Stealer That's Already Compromised 59K Servers
During monitoring of one of their Docker honeypots, the Beelzebub Research Team identified the PCPcat campaign, a highly sophisticated cyber-espionage operation targeting cloud infrastructure and development environments by exploiting CVE-2025-29927 and CVE-2025-55182 in Next.js and React frameworks to deploy PCPcat.