React2Shell is the name used in the provided content for CVE-2025-55182, a critical unauthenticated remote code execution vulnerability in React Server Components (RSC), rather than a standalone malware family. The flaw is described as stemming from unsafe deserialization in the RSC Flight protocol and can be triggered by a crafted HTTP POST to exposed RSC or Server Action endpoints on affected Node.js servers. The content states it affects React Server Components and downstream frameworks including Next.js, and references impacted libraries such as react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack. Reported exploitation involved arbitrary command execution, credential theft, cryptomining, backdoor deployment, botnet enrollment, ransomware delivery, and secret dumping. Threat activity in the content links exploitation to TeamPCP, which reportedly conducted mass exploitation beginning in December 2025, including a worm-driven campaign leveraging exposed Docker APIs, Kubernetes clusters, Ray dashboards, and Redis servers; affected sectors included technology, finance, healthcare, and government, with victims in Canada, Serbia, South Korea, the UAE, and the United States. Other reported exploitation is attributed to China-nexus actors including Earth Lamia, Jackpot Panda, and UNC5174, as well as the RondoDox botnet, which used the vulnerability to deploy cryptominers, botnet loaders, health checkers, Mirai variants, and malware such as SNOWLIGHT and VShell. High-confidence indicators and behaviors mentioned in the content include crafted POST requests to RSC endpoints, anomalous child_process execution after RSC requests, references such as rsc-action-id and vm# in logs, attempted theft of AWS configuration and credential files, use of PowerShell "cheap math" commands to verify exploitation, and at least one cited IP address, 45.149.154.81. Because the supplied content consistently describes React2Shell as the vulnerability name for CVE-2025-55182, this object should be understood as enrichment of that exploit name rather than a distinct malware strain.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
TeamPCP first gained notoriety in December 2025 in connection with the mass exploitation of the React2Shell vulnerability (CVE-2025-55182), a critical pre-authentication remote code execution flaw in React Server Components.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TeamPCP first gained notoriety in December 2025 in connection with the mass exploitation of the React2Shell vulnerability (CVE-2025-55182), a critical pre-authentication remote code execution flaw in React Server Components.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named exploit/vulnerability used by TeamPCP for mass exploitation to gain initial access in a worm-driven campaign affecting multiple sectors and countries.
Named exploitation activity referenced as being observed and ranked highly in exploitation telemetry.
Im Text als Beispiel für ein Supply-Chain-Risiko/Schwachstelle genannt; technische Details (Payload, TTPs, Ziele) werden nicht beschrieben.
React2Shell is a malicious payload deployed by the RondoDox botnet, exploiting the React Server Components vulnerability (CVE-2025-55182) to achieve remote code execution on vulnerable Next.js servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.