``Investigating Next.js React2Shell Exploitation"
Martin Mladenov, Max van der Horst, Alexandru Hossu, Rok Štular, Harm Griffioen, and Georgios Smaragdakis.
ACM Internet Measurement Conference (IMC) 2026.

Abstract:
Full-stack web development frameworks have become increasingly popular in recent years. One such framework, Next.js, is extensively used by one in five web developers. In December 2025, a critical vulnerability with the highest severity score of 10 was discovered, affecting Next.js through supply-chain propagation. It allows attackers to remotely execute code on vulnerable servers without user authentication and with a single malicious HTTP request. Additionally, public proof-of-concept exploits contributed to widespread exploitation.

In this paper, we investigate 13 million exploitation attempts targeting Next.js and characterize the malware deployed by attackers following successful exploitation. Leveraging our custom Next.js honeypots and reactive telescope, we identify 93 unique clusters of payloads performing a wide range of exploitation activity such as botnet installation, cryptomining, and infostealers. Our analysis also shows that, initially, exploitation attempts relied on the released proof-of-concept code, but they later evolved into more sophisticated and effective code variants that successfully evade defense mechanisms such as Web Application Firewalls. We identify that some threat actors measure the vulnerability of targets before deploying any malicious payloads and demonstrate the presence of informed application-layer scanners with prior knowledge of a set of vulnerable hosts, which they exclusively target. Moreover, we observe markers consistent with LLM-style code artifacts, pointing towards the emergence of AI-assisted attacks. In the process, we characterize the demographics of the infrastructure used to attack Next.js and discuss the shortcomings of defense capabilities.




Paper           :
bibtex          : [bibtex.html]