Attackers Use New Tool to Scan for React2Shell Exposure
ID: 8f44fb33-9554-5eb7-83c8-8ade667d83b6
STIX ID: report--8f44fb33-9554-5eb7-83c8-8ade667d83b6
Feed Name: Dark Reading
Threat Score
A newly disclosed critical RCE in React Server Components (CVE-2025-55182, "React2Shell") is being actively exploited: a toolkit dubbed "ILovePoop" has scanned millions of IPs and targeted government, financial, energy, and major corporate networks, with botnets and ransomware actors incorporating the exploit and attackers adopting resilient C2 techniques and large-scale reconnaissance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
