#React2Shell
The original React2shell PoC is now public. This is as bad as it gets – full RCE. You must upgrade now. There are mitigations in place in CDNs including Cloudflare, Netlify, Vercel and AWS (and sites on Workers aren't vulnerable to this sort of attack), but there are variants in the wild now.
GitHub - lachlan2k/React2Shell-CVE-2025-55182-original-poc: Original Proof-of-Concept's for React2Shell CVE-2025-55182
Original Proof-of-Concept's for React2Shell CVE-2025-55182 - lachlan2k/React2Shell-CVE-2025-55182-original-poc
github.com
December 5, 2025 at 11:13 AM
React2Shell exploitation frequency in GreyNoise dec 5-dec 6
December 7, 2025 at 4:14 PM
Researchers have found two new vulnerabilities in React Server Components while attempting to exploit the patches last week.

These are new issues, separate from the critical CVE last week. The patch for React2Shell remains effective for the Remote Code Execution exploit.
December 11, 2025 at 8:51 PM
For anyone that missed it, the React Server Components critical vulnerability has a name and website now

Please refer to this before sharing any supposed POCs

react2shell.com
React2Shell (CVE-2025-55182/CVE-2025-66478)
react2shell.com
December 4, 2025 at 10:06 AM
You can now scan for #react2shell in Burp Suite! To enable, install the Extensibility Helper bapp, go to the bambda tab and search for react2shell. Shout-out to Assetnote for sharing a quality detection technique!
December 4, 2025 at 3:05 PM
Per Sysdig, North Korean hackers are now exploiting React2Shell to drop EtherRAT, a remote access trojan that uses Ethereum smart contracts as C2

www.sysdig.com/blog/etherra...
EtherRAT: DPRK uses novel Ethereum implant in React2Shell attacks | Sysdig
A novel Ethereum-powered backdoor, EtherRAT, is being deployed through the React2Shell vulnerability (CVE-2025-55182). With multi-layer persistence, blockchain C2, and self-updating payloads, this mal...
www.sysdig.com
December 9, 2025 at 11:50 AM
A new blog this evening from Amazon Threat Intelligence detailing ongoing China-nexus cyber actors leveraging React2Shell (CVE-2025-55182): aws.amazon.com/blogs/securi...
China-nexus cyber threat groups rapidly exploit React2Shell vulnerability (CVE-2025-55182) | Amazon Web Services
Within hours of the public disclosure of CVE-2025-55182 (React2Shell) on December 3, 2025, Amazon threat intelligence teams observed active exploitation attempts by multiple China state-nexus threat g...
aws.amazon.com
December 5, 2025 at 1:06 AM
Hackers are running a large-scale campaign to steal credentials in an automated way after exploiting React2Shell (CVE-2025-55182) in vulnerable Next.js apps.
Hackers exploit React2Shell in automated credential theft campaign
Hackers are running a large-scale campaign to steal credentials in an automated way after exploiting React2Shell (CVE-2025-55182) in vulnerable Next.js apps.
www.bleepingcomputer.com
April 5, 2026 at 2:18 PM
👀 React2Shell attacker profiles fresh from GreyNoise telemetry: info.greynoise.io/hubfs/PDFs-S..., don't miss the latest contribution from GreyNoise Labs on React2Shell: www.labs.greynoise.io/grimoire/202...

#React2Shell #Nextjs #CVE202555182 #CVE #GreyNoise
December 9, 2025 at 6:59 PM
We paid $1 million to hackers to harden our firewall defenses.

Today we're telling the story of how we strengthened our WAF, disclosing a runtime mitigation layer for the first time, and how we partnered with
@Hacker0x01 to defend against React2Shell.

vercel.com/blog/our-mi...
Our $1 million hacker challenge for React2Shell - Vercel
We paid $1M to security researchers to break our WAF. Here's what we learned defending against React2Shell.
vercel.com
December 19, 2025 at 8:55 PM
Google is now tracking at least five Chinese cyber-espionage groups that are exploiting the React2Shell vulnerability for initial access.

The groups are UNC6600, UNC6586, UNC6588, UNC6595, and UNC6603. This is up from two at the beginning.

cloud.google.com/blog/topics/...
Multiple Threat Actors Exploit React2Shell (CVE-2025-55182) | Google Cloud Blog
Widespread exploitation of the React2Shell vulnerability (CVE-2025-55182) by multiple threat actors, including China and cyber criminals.
cloud.google.com
December 14, 2025 at 2:00 AM
Is nothing sacred?

Go out for dinner, overhear people talking react2shell in the wild.

Get me out of here.
April 15, 2026 at 12:09 AM
Update on CVE-2025-66478 (React2Shell):

An npm package has been released to scan and update affected Next.js apps. Use `npx fix-react2shell-next` to update to patched versions.

All users should update as soon as possible.

More details our blog:

nextjs.org/cve-2025-66478
Security Advisory: CVE-2025-66478
A critical vulnerability (CVE-2025-66478) has been identified in the React Server Components protocol. Users should upgrade to patched versions immediately.
nextjs.org
December 6, 2025 at 4:19 PM
Enjoy this blessed time, all
December 15, 2025 at 4:01 PM
Seeing a high volume of blocked #DNS queries to the domain linked to the #Mozi botnet & the #React2Shell exploit. This identified malicious domain is provided by our #threatintel partner, ThreatSTOP.

Our proactive DNS filtering is currently preventing these connections to keep you secure.
#infosec
February 11, 2026 at 5:06 PM
Over the weekend, ​Google's threat intelligence team linked five more Chinese hacking groups to attacks exploiting the maximum-severity React2Shell remote code execution vulnerability.
Google links more Chinese hacking groups to React2Shell attacks
Over the weekend, ​Google's threat intelligence team linked five more Chinese hacking groups to attacks exploiting the maximum-severity React2Shell remote code execution vulnerability.
www.bleepingcomputer.com
December 15, 2025 at 12:47 PM
Over 77,000 Internet-exposed IP addresses are vulnerable to the critical React2Shell remote code execution flaw (CVE-2025-55182), with researchers now confirming that attackers have already compromised over 30 organizations across multiple sectors.
React2Shell flaw exploited to breach 30 orgs, 77k IP addresses vulnerable
Over 77,000 Internet-exposed IP addresses are vulnerable to the critical React2Shell remote code execution flaw (CVE-2025-55182), with researchers now confirming that attackers have already compromised over 30 organizations across multiple sectors.
www.bleepingcomputer.com
December 6, 2025 at 7:07 PM
I've been ignoring the posts and warnings about React2Shell. I wrote my cautionary tale.

dev.to/blackgirlbyt...
The Worst Thing to Happen to React and Next.js: React2Shell
"I ain't reading all that. I'm happy for you tho, or sorry that happened." That was my internal...
dev.to
December 31, 2025 at 6:18 PM
📰 Botnet RondoDox Eksploitasi Celah React2Shell untuk Menyerang Server Next.js

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/01/02/rondodox-react2shell-nextjs-botnet/

#bot
ne#botnet##iota#malwarea#keamananr#siber.#nextce ##rcet#react2shello#rondodox
January 2, 2026 at 7:32 AM
Multiple China-linked threat actors began exploiting the React2Shell vulnerability (CVE-2025-55182) affecting React and Next.js just hours after the max-severity issue was disclosed.
React2Shell critical flaw actively exploited in China-linked attacks
Multiple China-linked threat actors began exploiting the React2Shell vulnerability (CVE-2025-55182) affecting React and Next.js just hours after the max-severity issue was disclosed.
www.bleepingcomputer.com
December 5, 2025 at 11:26 AM
A maximum severity vulnerability, dubbed 'React2Shell', in the React Server Components (RSC) 'Flight' protocol allows remote code execution without authentication in React and Next.js applications.
Critical React, Next.js flaw lets hackers execute code on servers
A maximum severity vulnerability, dubbed 'React2Shell', in the React Server Components (RSC) 'Flight' protocol allows remote code execution without authentication in React and Next.js applications.
www.bleepingcomputer.com
December 4, 2025 at 3:12 PM