REACT2SHELL: EXPLOITATION IN THE WILD
ID: 7a22c235-826b-590b-8c1d-6886a566f242
STIX ID: report--7a22c235-826b-590b-8c1d-6886a566f242
Feed Name: THE RAVEN FILE
*Executive summary:* This individual research details active exploitation of CVE-2025-55182 (React2Shell), a pre-auth RCE in React Server Components, and maps attacker infrastructure and indicators — including an open directory containing a 'next_target' list of high-profile domains, reuse of a distinctive multipart boundary string across hundreds of hosts, and deployment of sex.sh scripts that install XMRIG Monero miners; the report includes IPs, URLs, and wallet addresses and advises patching affected Next.js/React components.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
