Security researchers reported an active campaign exploiting React2Shell (CVE-2025-55182) in React.js and Next.js server components to achieve remote code execution and deploy XMRig for Monero mining. Darktrace observed the activity through its CloudyPots honeypot network, where an attacker abused an exposed, unauthenticated Docker daemon to launch a container, install utilities, retrieve Python components from Pastebin and a GitHub Gist, and validate exploitation with commands such as:
whoami
wget
The exploit chain used crafted Next.js server component payloads to trigger exceptions and leak command output, enabling shell execution on vulnerable targets.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
Using public mining-pool statistics, researchers estimated the React2Shell cryptojacking operation infected about 91 hosts. Despite that reach, the campaign earned only about 0.015 XMR, roughly £5 or $5.02.
Researchers assessed the React2Shell payload as AI-generated based on unusually verbose comments, an educational-use disclaimer, and GPTZero analysis estimating 76% of the code was AI-generated. The finding highlighted how LLMs can accelerate creation of functional exploitation tooling.
Darktrace detected an active campaign in its CloudyPots honeypot network exploiting React2Shell (CVE-2025-55182) through an exposed Docker daemon. The attacker spawned a malicious container, validated code execution, and used a Python exploit chain to deploy XMRig for Monero mining.
Ontinue analysts described VoidLink as a modular Linux malware framework targeting cloud and enterprise environments, with credential theft, cloud metadata probing, container and Kubernetes targeting, and kernel-level stealth. The report also noted signs the malware was built with assistance from an LLM coding agent.
Malicious versions of the official dYdX client libraries were published simultaneously to npm and PyPI, indicating likely compromise of maintainer publishing credentials. The npm package stole wallet seed phrases and device fingerprints, while the PyPI package also deployed a remote access trojan capable of arbitrary code execution.
In preparation for the dYdX supply-chain attack, the attacker registered the typosquatting domain dydx[.]priceoracle[.]site, which was later used to receive exfiltrated wallet seed phrases.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourcegovinfosecurity.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.