logo

ILOVEPOOP Toolkit Exploiting React2Shell Vulnerability to Deploy Malicious Payload

ID: 92e39c0c-ad5d-5de3-b75c-9eb886594756

STIX ID: report--92e39c0c-ad5d-5de3-b75c-9eb886594756

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-02-10

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A critical RCE vulnerability dubbed `React2Shell` (CVE-2025-55182) in Next.js/React Server Components was publicly disclosed on 2025-12-04 and saw active exploitation within ~20 hours via malicious HTTP POSTs targeting `/_next/server` and `/_next/flight`. The campaign is attributed to the "ILOVEPOOP" toolkit, which uses distinctive headers (e.g., `X-Nextjs-Request-Id:poop1234`, `Next-Action:x`), nine rotating scanner nodes, and two Netherlands-based command IPs (193.142.147.209, 87.121.84.24); advised mitigations include urgent patching, WAF rules to block the malicious headers, and blocking the known exploit servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.