logo

React2Shell Vulnerability Exploited in the Wild, Analysts Warn

ID: 08a98129-0e92-51ee-8dae-4ec9e22fb4cf

STIX ID: report--08a98129-0e92-51ee-8dae-4ec9e22fb4cf

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-02-10

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

WXA IASC reports rapid weaponization and active exploitation of CVE-2025-55182 (React2Shell), with honeypot captures within ~20 hours of disclosure and sustained scanning targeting Next.js server paths; a single-operator toolkit dubbed ILOVEPOOP is fingerprinted by distinct headers, rotation of User-Agents, and a nine-node scanner infrastructure centered around two Netherlands-hosted IPs (193.142.147.209 and 87.121.84.24), and defenders are advised to patch, hunt for Next.js internal headers and canary IDs, and prioritize exposure reduction and containment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.