A new, particularly serious security flaw in the world of web development has raised global alarm. Over the weekend, the Google Threat Intelligence Group (GTIG) revealed that at least five additional Chinese hacking groups are actively involved in attacks exploiting the React2Shell, one of the most dangerous to be identified in recent years in popular JavaScript frameworks.

What is React2Shell and why is it considered a critical threat?
The vulnerability, which is tracked as CVE-2025-55182, allows remote code execution (RCE) via a single HTTP request. In simple terms, an unauthorized attacker could take control of a React or Next.js application without requiring any user interaction.
See also: Windows RasMan vulnerability allows arbitrary code execution
The issue affects specific versions of the React library — 19.0, 19.1.0, 19.1.1, and 19.2.0 — released in the past year. Packages such as react-server-dom-webpack, react-server-dom-parcel , and react-server-dom-turbopack are considered vulnerable in their default configurations, which dramatically increases the attack surface.
From discovery to exploitation within hours
The speed with which threat actors exploited the vulnerability has raised serious concerns. According to the Amazon Web Services (AWS), Chinese groups such as Earth Lamia and Jackpot Panda began using React2Shell just hours after it was publicly disclosed.
At the same time, Palo Alto Networks reported dozens of confirmed breaches of organizations, with attackers exploiting the flaw to execute commands, steal AWS configuration files, access credentials , and other critical data.

New Chinese teams in the spotlight
Google's latest report revealed the involvement of five more Chinese cyberespionage groups. These include:
- UNC6600, which utilizes the MINOCAT tunneling software
- UNC6586, connected to the SNOWLIGHT downloader
- UNC6588, who develops the COMPOOD backdoor
- UNC6603, with an upgraded version of the HISONIC backdoor
- UNC6595, responsible for the ANGREBEL.LINUX RAT
The presence of so many different groups suggests that React2Shell has quickly become a “front-line weapon” for state-sponsored cyberespionage operations.
See also: CISA added Sierra Wireless Routers vulnerability to KEV List
Underground forums and mass dissemination of attack tools
According to GTIG, CVE-2025-55182 has become a major topic of discussion in underground cyber forums, where threat actors are sharing scanning tools, proof-of-concept exploits, and practical instructions for successfully exploiting the vulnerability.
Even more worrying is the fact that the attacks are not only involving state actors. Researchers have identified Iranian threat actors, but also financially motivated attackers who install XMRig crypto-miners on unpatched systems, turning web servers into cryptocurrency mining machines.
Tens of thousands of vulnerable systems worldwide
Data from independent monitoring organizations is revealing. The Shadowserver Foundation tracks more than 116,000 vulnerable IP addresses, with over 80,000 located in the United States. At the same time, GreyNoise recorded over 670 unique IPs actively attempting to exploit React2Shell in just 24 hours.
The attacks come from all over the world, with significant activity in the US, Europe, Asia and Australia, demonstrating the global scale of the threat.
See also: MITRE: The 25 most dangerous software vulnerabilities of 2025
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

When security "throws" the internet
The severity of the situation was also highlighted on December 5th, when Cloudflare linked a widespread global outage to urgent protections for React2Shell. The incident highlighted how deeply embedded React is in the modern web and how devastating such vulnerabilities can be.
A bell for developers and organizations
React2Shell is not just another CVE. It is a stark reminder that popular frameworks are an attractive target and that delaying updates can prove fatal. For organizations, promptly upgrading, monitoring traffic, and hardening infrastructure are no longer optional actions, but a matter of survival in the modern digital war.
Source: www.bleepingcomputer.com
