Operation PCPcat is a threat campaign tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 24, 2025; most recent activity December 24, 2025.
Operation PCPcat is a threat campaign that targets web applications built on Next.js and React, exploiting those environments to compromise servers. The campaign has achieved a large scale, impacting over 59,000 servers, highlighting adversaries' focus on popular JavaScript frameworks and their infrastructure.
Operation PCPcat has compromised 59,128 Next.js and React servers in under 48 hours, exploiting critical vulnerabilities CVE-2025-29927 and CVE-2025-66478. The attackers utilized prototype pollution in JSON payloads to…