logo

React2Shell (CVE-2025-55182): Node.js RCE Against a Production Next.js App

ID: 59614f76-168b-5e3a-ba24-e4536db69841

STIX ID: report--59614f76-168b-5e3a-ba24-e4536db69841

Feed Name: Hunt.io Blog

Threat Score
85/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This report documents an active exploitation of CVE-2025-55182 (React2Shell) against a Next.js application, confirming remote code execution via Node.js spawnSync through PoC signatures in logs. The attackers attempted a six-stage campaign—downloading Mirai-style bot binaries, running a 'nuts' IoT payload with a campaign tag (reactOnMynuts), using base64-encoded custom downloaders, and deploying persistence scripts across four C2 servers—while container restrictions limited full compromise; nevertheless, the incident produced 330 file-integrity alerts and exposed a JWT for a user account. The report includes extracted scripts, IOCs (four C2 IPs, file artifacts), infrastructure analysis, and MITRE ATT&CK mappings to support remediation and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.