ILOVEPOOP Toolkit Exploiting React2Shell Vulnerability to Deploy Malicious Payload
ID: 92e39c0c-ad5d-5de3-b75c-9eb886594756
STIX ID: report--92e39c0c-ad5d-5de3-b75c-9eb886594756
Feed Name: cybersecurityNews.com
A critical RCE vulnerability dubbed `React2Shell` (CVE-2025-55182) in Next.js/React Server Components was publicly disclosed on 2025-12-04 and saw active exploitation within ~20 hours via malicious HTTP POSTs targeting `/_next/server` and `/_next/flight`. The campaign is attributed to the "ILOVEPOOP" toolkit, which uses distinctive headers (e.g., `X-Nextjs-Request-Id:poop1234`, `Next-Action:x`), nine rotating scanner nodes, and two Netherlands-based command IPs (193.142.147.209, 87.121.84.24); advised mitigations include urgent patching, WAF rules to block the malicious headers, and blocking the known exploit servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
