Attackers compromised a tech-sector organization's Linux host by exploiting CVE-2025-55182 ("React2Shell") in a vulnerable Next.js 15.4.6 and React 19.1.0 application, then used the access for overlapping malicious operations. Huntress linked the intrusion and later reinfection to multiple actor clusters: one ran a Monero miner disguised as /var/tmp/systemd-logind and mining to 62.60.246[.]210:443, another deployed a multi-revenue botnet using XMRig, EarnFM, and Repocket, and a third harvested credentials and conducted broad data exfiltration. The attackers also established eight persistence mechanisms, attempted to disable the Huntress agent, and wiped logs to hinder investigation.
The incident was complicated because the system's legitimate user, a developer, was actively using OpenAI Codex for software development and to troubleshoot suspicious behavior on the same host. Huntress found that some commands initially flagged as suspicious were actually AI-generated administrative actions, while the real compromise included theft of SSH keys, cloud credentials, API tokens, shell history, and system metadata. The case showed that AI-assisted remediation can reduce visible symptoms without removing root cause, and that human-led DFIR and continuous EDR telemetry were necessary to separate legitimate automation from attacker activity and uncover the full scope of the breach.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
In a second write-up, Huntress expanded the case with a three-actor breakdown, persistence details, exfiltration findings, and its assessment that CVE-2025-55182 exploitation likely drove the intrusion and reinfection. The follow-up also highlighted the limits of AI-assisted remediation without continuous EDR telemetry and human oversight.
Across the compromise, attackers created eight persistence mechanisms, attempted to disable the Huntress agent, and wiped logs. These actions helped maintain access and hinder investigation and remediation.
Huntress assessed the initial intrusion, and a later reinfection, as consistent with exploitation of CVE-2025-55182 ("React2Shell") against the victim organization's Next.js 15.4.6 and React 19.1.0 application. Multiple threat actors subsequently operated on the same host.
Huntress publicly described the Linux incident and explained how legitimate Codex activity initially masked symptoms and complicated SOC triage alongside real attacker behavior. The write-up emphasized the need for human analysts to distinguish AI-assisted user actions from malicious activity.
Huntress found evidence of credential harvesting and exfiltration of sensitive materials including SSH keys, cloud credentials, API tokens, shell history, and system metadata. The incident involved both theft of secrets and broader data exfiltration from the compromised host.
Analysts determined the host was affected by at least three distinct activity clusters: a cryptominer operator, a botnet operator deploying XMRig, EarnFM, and Repocket with persistence, and a third actor conducting credential harvesting and mass data exfiltration. This separated legitimate Codex activity from real malicious actions on the system.
The legitimate user of the compromised host used OpenAI Codex both for software development and to troubleshoot suspicious system behavior. Some AI-generated commands resembled attacker tradecraft, creating substantial noise during SOC triage.
A Monero cryptominer running as /var/tmp/systemd-logind was active since boot on the affected Linux endpoint. Huntress observed it mining to 62.60.246[.]210:443.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.