React2Shell Vulnerability Exploited in the Wild, Analysts Warn
ID: 08a98129-0e92-51ee-8dae-4ec9e22fb4cf
STIX ID: report--08a98129-0e92-51ee-8dae-4ec9e22fb4cf
Feed Name: GBHackers
WXA IASC reports rapid weaponization and active exploitation of CVE-2025-55182 (React2Shell), with honeypot captures within ~20 hours of disclosure and sustained scanning targeting Next.js server paths; a single-operator toolkit dubbed ILOVEPOOP is fingerprinted by distinct headers, rotation of User-Agents, and a nine-node scanner infrastructure centered around two Netherlands-hosted IPs (193.142.147.209 and 87.121.84.24), and defenders are advised to patch, hunt for Next.js internal headers and canary IDs, and prioritize exposure reduction and containment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
