Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityrapid-weaponizationproof-of-concept-releaseopen-source-dependency-vulnerability

Active Exploitation of React2Shell (CVE-2025-55182) in React Server Components

Updated 2mo agoFirst seen Jan 27, 20264 sources

Threat actors are actively exploiting React2Shell (CVE-2025-55182), a critical remote code execution flaw in the Flight protocol used for client-server communication in React Server Components. The issue is attributed to insecure deserialization that can allow unauthorized code execution on vulnerable servers, with observed targeting across insurance, e-commerce, and IT organizations. Reported payloads include the XMRig cryptocurrency miner as well as multiple botnets and remote access tooling; campaigns observed against Russian entities deployed RustoBot and Kaiji, while other activity distributed malware such as CrossC2, Tactical RMM, VShell, and EtherRAT.

Affected packages include react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack in versions 19.0, 19.1.0, 19.1.1, and 19.2.0, with fixes available in 19.0.1, 19.1.2, and 19.2.1. Separate reporting highlighted that attackers leveraged a public proof-of-concept (PoC) for React2Shell and began targeting organizations within hours, reinforcing that rapid weaponization is now common; defenders are advised to patch and also perform post-patch validation, including checking for indicators of compromise, verifying Next.js and dependency versions, rebuilding projects after updates, and confirming lockfiles no longer reference vulnerable package versions.

Share:
Active Exploitation of React2Shell (CVE-2025-55182) in React Server Components
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jan 27, 20265mo ago

BI.ZONE details active React2Shell exploitation and malware variants

Reporting on active exploitation of CVE-2025-55182 described region-specific payloads, with Russian targets seeing RustoBot and Kaiji and other regions seeing CrossC2/Cobalt Strike, Tactical RMM, VShell, EtherRAT, and Sliver. Researchers also documented persistence via systemd and cron, anti-forensics, and DNS-tunneled exfiltration in some cases.

Patches released for affected React Server Components packages

Patched releases were made available for vulnerable React Server Components packages affected by CVE-2025-55182, including react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack across several 19.x versions. Despite the fixes, later reporting said exploitation continued against unpatched deployments.

Jan 1, 20266mo ago

Darktrace detects World Leaks intrusion at healthcare organization

In January 2026, Darktrace detected a World Leaks intrusion at a healthcare organization involving command-and-control via Cloudflare Tunnel and suspicious external IPs, plus exfiltration to MEGA and Backblaze. The incident was notable because the affiliate both exfiltrated data and encrypted systems, contradicting World Leaks' claimed extortion-only model.

Dec 13, 20256mo ago

GTIG links React2Shell exploitation to China- and Iran-nexus actors

Google Threat Intelligence Group reported widespread exploitation of CVE-2025-55182 beginning the previous week, involving multiple espionage and financially motivated clusters. GTIG said China-nexus groups UNC6600 and UNC6603 deployed tools including MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX, noted likely Iran-nexus participation, and published hunting IOCs and mitigation guidance.

Multiple Threat Actors Race to Exploit React2Shell Across Espionage and Criminal Operations - Austin Larsen
Dec 1, 20257mo ago

Attackers begin exploiting React2Shell against organizations

Campaigns exploiting CVE-2025-55182 ("React2Shell") were first observed in December 2025, targeting organizations including insurance, e-commerce, and IT entities. Reports describe rapid weaponization after vulnerability details became public and use of payloads such as XMRig, botnets, and remote access tools.

Oct 1, 20259mo ago

World Leaks likely compromises healthcare victim via Fortigate

Darktrace said a January 2026 healthcare intrusion linked to World Leaks likely began with the compromise of a Fortigate appliance in October 2025. The attackers then used compromised credentials and later moved through the environment using tools and protocols including PsExec, WinRM, RDP, SMB, and SSH.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

19 LINKEDOpen in app
Vulnerabilities
1 linked
Affected products
5 linked
React Server ComponentsSnortNext.JsSnortSnort
Organizations
4 linked
BI.ZONETotolinkRapid7SC Media
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Active Exploitation of React2Shell (CVE-2025-55182) in React Server Components | Mallory