Attackers Exploit React2Shell Vulnerability to Target IT Sector Systems
ID: ac559b6c-7f90-5105-a544-96e463f26660
STIX ID: report--ac559b6c-7f90-5105-a544-96e463f26660
Feed Name: GBHackers
**Critical active exploitation of CVE-2025-55182 (React2Shell) in react-server-dom packages is enabling remote code execution across multiple sectors; adversaries have rapidly deployed diverse malware (XMRig, Kaiji, RustoBot, Sliver, CrossC2/Cobalt Strike, VShell, EtherRAT), created persistent backdoors and cron/systemd persistence, and used DNS tunneling and SSH key insertion for persistence and exfiltration — organizations must immediately update affected packages (patched versions 19.0.1, 19.1.2, 19.2.1+), rebuild projects, verify lockfiles, and hunt for provided IOCs and unauthorized services.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
