Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
WXA IASC identifies a distinct operator-level toolkit we refer to as the ILOVEPOOP React2Shell toolkit. It accounts for 672 exploit attempts across nine scanner nodes, all exhibiting an identical fingerprint.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
"CVE-2025-55182, also known as React2Shell... It's a remote code execution (RCE) vulnerability in React Server Components... With no more than a single Web request — sometimes, with no authentication required — attackers can exploit React2Shell to take full control of vulnerable Web servers."
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly documented toolkit used to scan for and attempt exploitation of React2Shell in React Server Components and Next.js applications. Nine nodes share spoofed Next.js headers, per-attempt ilovepoop_* identifiers, a six-path endpoint sweep, and 11 rotating User-Agents. One node is a central Netherlands-hosted exploitation server. The report also observed delivery of an HTTP-shaped exploit payload to a POP3 sensor, but does not establish successful exploitation or compromise.
A newly discovered scanning/reconnaissance toolkit used to probe large numbers of IPs to identify systems potentially vulnerable to React2Shell (CVE-2025-55182), apparently in support of follow-on exploitation against high-value networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.