A critical remote code execution vulnerability, CVE-2025-55182, was discovered in Next.js 13+ and React Server Components, allowing attackers to execute arbitrary code via a deserialization flaw in the Server Actions feature. Following the public disclosure, multiple attack campaigns exploited this vulnerability, resulting in widespread compromises, including the deployment of cryptocurrency miners, persistent malware, and advanced implants such as EtherRAT, which leverages Ethereum smart contracts for command and control.
Security researchers and developers responded by analyzing the technical root cause of the vulnerability, documenting real-world exploitation, and developing tools to detect and remediate infections that persist after patching. Notably, new forensic tools were released to scan for indicators of compromise left behind by attackers, including fake services, malicious cron jobs, and unauthorized system modifications. The sophistication of some payloads, such as EtherRAT, suggests involvement from advanced threat actors, including DPRK-linked groups, and highlights the need for comprehensive post-patch incident response for affected environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A developer introduced NeuroLint, an AST-based forensics tool for React/Next.js environments, to scan for more than 80 indicators of compromise and help automate remediation. The tool was recommended for organizations that ran affected React or Next.js versions during the December 3-7 exposure period, even if they had already patched.
At least 415 servers were reported infected with persistent malware after exploitation of CVE-2025-55182, including cryptominers and fake services. Reports emphasized that patching the vulnerability alone would not remove malware or persistence left behind on already compromised hosts.
On December 5, 2025, Sysdig Threat Research identified EtherRAT on a Next.js application compromised through the newly disclosed CVE-2025-55182. The implant used Ethereum smart contracts for decentralized C2 and established multiple Linux persistence mechanisms.
Systems running React 19 or Next.js 15-16 were reportedly exposed to active exploitation during the December 3-7, 2025 window. The campaign used the pre-authentication RCE flaw to gain initial access and deploy follow-on payloads.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
news.ycombinator.com
Open sourcesysdig.com
Open sourceosintteam.blog
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.