logo

Multiple Threat Actors Exploit React2Shell (CVE-2025-55182)

ID: cd1ff6c2-1882-5b79-ad5e-e97668932dd8

STIX ID: report--cd1ff6c2-1882-5b79-ad5e-e97668932dd8

Feed Name: Threat Intelligence

Threat Score
90/100

Date Published: 2025-12-12

Date Updated: 2026-04-27

Author: Google Threat Intelligence Group

...
...

GTIG reports active, widespread exploitation of a critical unauthenticated RCE in React Server Components (CVE-2025-55182 / “React2Shell”) enabling remote code execution; multiple threat clusters—ranging from opportunistic cybercriminals to China‑nexus espionage groups—have used the flaw to deploy tunnellers (MINOCAT), downloaders (SNOWLIGHT), backdoors (HISONIC, COMPOOD), and XMRIG miners, with observed persistence mechanisms, diverse payload formats, and global impact on unpatched React/Next.js workloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.