Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
Malware

React2Shell

React2Shell is the name used in the provided content for CVE-2025-55182, a critical unauthenticated remote code execution vulnerability in React Server Components (RSC) affecting Node.js servers and downstream frameworks such as Next.js. The flaw is described as stemming from unsafe deserialization in the RSC Flight protocol and can be triggered by a crafted HTTP POST request to exposed RSC or Server Action endpoints, allowing arbitrary code execution on affected servers. Reported affected components include react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack, with impacted ecosystems including React 19.x and Next.js 15.x/16.x using the App Router. The content states that exploitation began rapidly after disclosure and that React2Shell has been used both as a web server exploitation technique for initial footholds in containerized workloads and in broad internet exploitation campaigns. Observed post-exploitation activity includes credential theft, cryptomining, backdoor deployment, botnet integration, ransomware deployment, reverse shells, and theft of AWS configuration and credential files. Threat activity in the content is associated with TeamPCP for container initial access use, the RondoDox botnet for exploitation of vulnerable Next.js servers and deployment of malware and cryptominers, and China-linked actors including Earth Lamia, Jackpot Panda, UNC5174, and Salt Typhoon affiliates. Additional malware or tooling reportedly deployed via exploitation includes Mirai variants, SNOWLIGHT, VShell, Cobalt Strike, cryptominers, and LockBit 4.0. The content notes targeting across multiple sectors and geographies, including over 30 affected organizations across sectors, and describes indicators such as anomalous POST requests to /rsc or Server Action endpoints, child_process execution following RSC requests, rsc-action-id and vm# artifacts in logs, specific exploit payload patterns, and at least one cited IP address, 45.149.154.81.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

2 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1190Exploit Public-Facing ApplicationEvidence2

React2Shell: A web server exploitation technique used for initial foothold in containerized workloads

Execution

1 technique
T1203Exploitation for Client ExecutionEvidence1

One of the techniques referenced in related campaigns is React2Shell, where vulnerable web applications are abused to achieve remote command execution and drop into an interactive shell.

INDICATORS OF COMPROMISE

IOCs tracked for this family

35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
24 tracked

IPs, domains, and DNS infrastructure linked to this family.

Other
11 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app1 month ago
ip.v4●●●●●●●●●●●●View more in app2 months ago
ip.v4●●●●●●●●●●●●View more in app2 months ago
ip.v4●●●●●●●●●●●●View more in app3 months ago
ip.v4●●●●●●●●●●●●View more in app3 months ago
ip.v4●●●●●●●●●●●●View more in app5 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching35

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping2

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.