HomeSecurityChinese hackers exploit React2Shell vulnerability

Chinese hackers exploit React2Shell vulnerability

A serious vulnerability in the popular React and Next.js has raised concerns among security analysts, as it allows remote code execution without authentication. The issue, known as React2Shell (CVE-2025-55182), was discovered on December 3, 2025 , and became the target of attacks just hours after it was made public.

React2Shell

What is React2Shell and How Does It Work?

React2Shell is a deserialization vulnerability in the “Flight” protocol of React Server Components (RSC). It allows attackers to execute arbitrary JavaScript code in the server environment, exposing applications and infrastructure to significant risks.

For Next.js, there was a separate identifier CVE-2025-66478, but it was ultimately dismissed as a duplicate of React2Shell on the CVE list, emphasizing that the vulnerability affects both frameworks.

The exploit is relatively simple and does not require prior credentials, which significantly increases the risk. Wiz analysts estimate that 39% of observable cloud environments are vulnerable, while thousands of projects depend on the React and Next.js libraries.

See also: Vulnerability in NVIDIA Triton allows attackers to cause DoS attack

First Attacks and Danger From State-Level Groups

According to a report by Amazon Web Services (AWS), Chinese threat groups, such as Earth Lamia and Jackpot Panda, began exploiting React2Shell almost immediately after the CVE was made public.

“Within hours of the disclosure, AWS recorded active exploitation attempts by multiple Chinese state-owned groups,” the report states.

AWS honeypots also detected activity from infrastructure based in China, but did not attribute it to a specific group, reinforcing the sense that the exploitation is widespread and coordinated .

Targets and Geographic Scope of Attacks

Chinese hackers exploit React2Shell vulnerability

The Earth Lamia team focuses on web application vulnerabilities and typically targets:

  • financial institutions
  • logistics and retail companies
  • universities
  • government organizations

Their attacks are recorded mainly in Latin America, the Middle East and Southeast Asia.

See also: Cacti vulnerability allows remote code execution

Accordingly, Jackpot Panda focuses on East and Southeast Asia, focusing on gathering information on corruption and internal security.

Published PoC and Active Exploitation

Researcher Lachlan Davidson, who reported the vulnerability, warned of fake exploits online. However, confirmed PoCs have appeared on GitHub by Stephen Fewer (Rapid7) and Joe Desimone (Elastic Security).

The attacks recorded by AWS included:

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

  • running Linux commands like whoami and id
  • create files /tmp/pwned.txt
  • attempts to read /etc/passwd/

Analysts note that attackers are not limited to automated scans, but are actively adapting their techniques to real targets.

See also: Hackers exploit command injection vulnerability in Array AG Gateways

Chinese hackers exploit React2Shell vulnerability

Protective Measures and Preventive Security

React and Next.js have released security updates to address CVE-2025-55182. Organizations are urged to:

  1. Implement new versions immediately.
  2. Assess all cloud and server for vulnerabilities.
  3. Use tools like the React2Shell scanner released by Assetnote on GitHub to detect vulnerable systems.
  4. Strengthen network securityby restricting access to React and Next.js servers.

React2Shell is a stark reminder that even the most popular libraries can be the target of rapid and coordinated attacks, and that prompt patching and monitoring is critical to application security.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS