logo

Attackers Exploit React2Shell Vulnerability to Target IT Sector Systems

ID: ac559b6c-7f90-5105-a544-96e463f26660

STIX ID: report--ac559b6c-7f90-5105-a544-96e463f26660

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-01-27

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Critical active exploitation of CVE-2025-55182 (React2Shell) in react-server-dom packages is enabling remote code execution across multiple sectors; adversaries have rapidly deployed diverse malware (XMRig, Kaiji, RustoBot, Sliver, CrossC2/Cobalt Strike, VShell, EtherRAT), created persistent backdoors and cron/systemd persistence, and used DNS tunneling and SSH key insertion for persistence and exfiltration — organizations must immediately update affected packages (patched versions 19.0.1, 19.1.2, 19.2.1+), rebuild projects, verify lockfiles, and hunt for provided IOCs and unauthorized services.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.