HomeSecurityHackers exploit React2Shell to hijack web traffic via NGINX

Hackers exploit React2Shell to hijack web traffic via NGINX

Cybersecurity researchers have revealed details of an active web traffic hijacking campaign targeting NGINX and management panels such as Baota (BT) in an attempt to funnel traffic through the attacker's infrastructure.

See also: RondoDox Botnet Exploits React2Shell Vulnerability

NGINX

Datadog Security Labs observed that threat actors associated with the recent React2Shell exploit (CVE-2025-55182, CVSS score: 10.0) are using malicious NGINX configurations to execute the attack.

The activity involves using shell scripts to inject malicious configurations into NGINX, an open-source reverse proxy and load balancer for managing web traffic. These “location” configurations are designed to intercept incoming requests to certain predefined URL paths and redirect them to domains under the attackers’ control via the “proxy_pass” directive.

The scripts are part of a multi-layered tool that facilitates persistence and the creation of malicious configuration files that embed malicious instructions to redirect web traffic.

See also: React2Shell: The serious bug that caused unrest on the internet

Hackers exploit React2Shell to hijack web traffic via NGINX

The elements of the tool include:

  • zx.sh, which acts as the orchestrator for executing subsequent steps via legitimate utilities such as curl or wget. If these programs are blocked, it creates a raw TCP connection to send an HTTP request.
  • bt.sh, which targets the Baota (BT) Management Panel to replace the NGINS configuration files.
  • 4zdh.sh, which lists common NGINX configuration locations and minimizes errors when creating new configuration.
  • zdh.sh, which focuses primarily on NGINX configurations in Linux or containerized environments and targets top-level domains (TLDs) such as .in and .id.
  • ok.sh, which generates a report detailing all active NGINX traffic hijacking rules.

“The tool contains target discovery and several scripts designed for persistence and the creation of malicious configuration files containing instructions for redirecting web traffic.“

See also: React2Shell: The Log4j moment for front end development

Hackers exploit React2Shell to hijack web traffic via NGINX

This follows the discovery of a coordinated reconnaissance campaign targeting Citrix ADC Gateway and Netscaler Gateway using tens of thousands of home proxy servers and a unique Microsoft Azure IP address (“52.139.3[.]76”) to discover connection tables.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS