A GitHub repository masquerading as a vulnerability scanner for CVE-2025-55182, also known as React2Shell, was discovered to be distributing malware instead of providing legitimate security functionality. The tool, named React2shell-scanner and hosted by the user niha0wa, embedded a hidden payload within its code that executed a PowerShell command via mshta.exe to download additional malicious scripts from a remote server. This attack specifically targeted security professionals and researchers investigating the React2Shell vulnerability, leveraging their trust in open-source platforms to compromise Windows devices. GitHub responded by removing the repository after community reports and warnings from cybersecurity researchers.
Simultaneously, attackers have been actively exploiting the React2Shell vulnerability in the wild, particularly targeting Japanese organizations. Initial exploitation campaigns deployed cryptocurrency miners, but more recent attacks have introduced a sophisticated remote access trojan named ZnDoor. This malware is delivered through shell commands executed after successful exploitation of CVE-2025-55182, establishing persistent backdoor access and encrypted command and control communications. The emergence of ZnDoor marks a significant escalation in the threat landscape for organizations using vulnerable React/Next.js applications, highlighting the dual risks of both malicious "security" tools and direct exploitation by advanced malware.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
After the repository was identified as malicious, GitHub removed it from the platform. Reports noted that cached copies or forks could still remain accessible despite the takedown.
A GitHub repository named React2shell-scanner, presented as a scanner for CVE-2025-55182, was found to contain a hidden malicious payload in react2shellpy.py. The script used mshta.exe and base64-encoded PowerShell to fetch and execute a remote file, targeting Windows systems.
NTT Security analysts uncovered and described the infection chain in which React2Shell exploitation was used to install ZnDoor, along with details on the malware's command structure and behavior. Their findings highlighted the campaign's persistence, evasion, and network tunneling capabilities.
Attackers escalated the React2Shell campaign by using the vulnerability to execute shell commands that downloaded and launched ZnDoor on affected devices. This marked a shift from miner deployment to a more advanced persistent backdoor capability.
Since December 2025, Japanese organizations have faced a surge of attacks exploiting the critical React/Next.js remote code execution flaw CVE-2025-55182, also called React2Shell. Early observed exploitation primarily deployed cryptocurrency miners on compromised systems.
ZnDoor, a remote access trojan later linked to React2Shell exploitation, had been active since at least December 2023. The malware was designed to provide persistent backdoor access with encrypted command-and-control communications and evasion features.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.