React2Shell
React2Shell is the name used in the provided content for CVE-2025-55182, a critical unauthenticated remote code execution vulnerability in React Server Components (RSC) affecting Node.js servers and downstream frameworks such as Next.js. The flaw is described as stemming from unsafe deserialization in the RSC Flight protocol and can be triggered by a crafted HTTP POST request to exposed RSC or Server Action endpoints, allowing arbitrary code execution on affected servers. Reported affected components include react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack, with impacted ecosystems including React 19.x and Next.js 15.x/16.x using the App Router. The content states that exploitation began rapidly after disclosure and that React2Shell has been used both as a web server exploitation technique for initial footholds in containerized workloads and in broad internet exploitation campaigns. Observed post-exploitation activity includes credential theft, cryptomining, backdoor deployment, botnet integration, ransomware deployment, reverse shells, and theft of AWS configuration and credential files. Threat activity in the content is associated with TeamPCP for container initial access use, the RondoDox botnet for exploitation of vulnerable Next.js servers and deployment of malware and cryptominers, and China-linked actors including Earth Lamia, Jackpot Panda, UNC5174, and Salt Typhoon affiliates. Additional malware or tooling reportedly deployed via exploitation includes Mirai variants, SNOWLIGHT, VShell, Cobalt Strike, cryptominers, and LockBit 4.0. The content notes targeting across multiple sectors and geographies, including over 30 affected organizations across sectors, and describes indicators such as anomalous POST requests to /rsc or Server Action endpoints, child_process execution following RSC requests, rsc-action-id and vm# artifacts in logs, specific exploit payload patterns, and at least one cited IP address, 45.149.154.81.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique
Initial Access
IOCs tracked for this family
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
Recent activity
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A web server exploitation technique used for initial foothold in containerized workloads.
Named exploitation activity referenced as being observed and ranked highly in exploitation telemetry.
Im Text als Beispiel für ein Supply-Chain-Risiko/Schwachstelle genannt; technische Details (Payload, TTPs, Ziele) werden nicht beschrieben.
React2Shell is a malicious payload deployed by the RondoDox botnet, exploiting the React Server Components vulnerability (CVE-2025-55182) to achieve remote code execution on vulnerable Next.js servers.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.