The React2Shell continues to be heavily observed, with malicious actors leveraging the critical security vulnerability in React Server Components (RSC) to distribute crypto miners and a number of previously undocumented malware families, according to new discoveries from Huntress.
See also: Crypto user loses $9,000 in seconds after clicking on Instagram ad

This includes a Linux backdoor called PeerBlight, a reverse proxy tunnel called CowTunnel , and a post-exploit implant based on the Go language referred to as ZinFoq.
The cybersecurity firm said it has observed attackers targeting numerous organizations via CVE-2025-55182, a critical security vulnerability in RSC that allows unauthenticated remote code execution. Since December 8, 2025, these efforts have targeted a wide range of sectors, most notably the construction and entertainment industries.
The first recorded attempt to exploit a Windows endpoint by Huntress dates back to December 4, 2025, when an unknown malicious actor exploited a vulnerable instance of Next.js to drop a shell script, followed by commands to drop a crypto miner and a Linux backdoor.
In two other cases, attackers were observed launching discovery commands and attempting to download various payloads from a command and control (C2) server. Some notable attacks also targeted Linux hosts to drop the XMRig and leveraged a publicly available GitHub tool to identify vulnerable instances of Next.js before launching the attack.
See also: Exposed JDWP interfaces lead to crypto mining and DDoS

A brief description of some of the payloads downloaded in these attacks is as follows:
– sex.sh: A bash script that retrieves XMRig 6.24.0 directly from GitHub.
– PeerBlight: A Linux backdoor that shares some code overlap with two malware families, RotaJakiro and Pink, that came to light in 2021. It installs a systemd service to ensure persistence and disguises itself as a “ksoftirqd” daemon process to evade detection.
– CowTunnel: A reverse proxy tunnel that initiates an outbound connection to Fast Reverse Proxy (FRP) controlled by attackers, effectively bypassing firewalls configured to only monitor incoming connections.
– ZinFoq: A Linux ELF binary that implements a meta-exploit framework with interactive shell capabilities, file operations, network displacement, and timestamp modification capabilities.
– d5.sh: An installation script responsible for deploying the Sliver C2 framework.
– fn22.sh: A variant of “d5.sh” with an additional self-update mechanism to retrieve a new version of the malware and restart it.
– wocaosinm.sh: A variant of the Kaiji DDoS malware that incorporates remote management, persistence, and evasion capabilities.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Hackers exploit Craft CMS vulnerability to install cryptominer

PeerBlight supports capabilities to establish communications with a hardcoded C2 server (“185.247.224[.]41:8443”), allowing it to upload, download, delete files, create a reverse shell, modify file permissions, execute arbitrary binaries, and update itself. The backdoor also uses a domain generation algorithm (DGA) and the BitTorrent Distributed Hash Table (DHT) as backup C2 mechanisms.
