React2Shell (CVE-2025-55182), a CVSS 10.0 unauthenticated remote code execution vulnerability affecting React Server Components and applications using them, including Next.js, triggered widespread exploitation after its December 3, 2025 disclosure. The flaw involves unsafe handling of serialized input and can be exploited with a single HTTP POST request. Honeypots recorded attempts within approximately 20 hours, and CrowdSec subsequently observed daily attacking IPs rise from roughly 500 to more than 10,000 at the December 11 peak. Researchers documented reverse shells, persistent XMRig cryptocurrency miners, Mirai botnet payloads and activity associated with suspected China-linked operators. Targeting expanded from banks and healthcare organizations to smaller websites and exposed development servers. The Next.js-specific identifier CVE-2025-66478 was rejected as a duplicate of CVE-2025-55182.
Exploitation later concentrated around a smaller set of high-volume sources: GreyNoise recorded 1,419,718 attempts during January 26–February 2, 2026, with two IP addresses generating 56% of activity and delivering distinct reverse-shell and cryptomining payloads. An April WhoisXML API report identified the previously undocumented ILOVEPOOP toolkit, linking nine scanner nodes through shared exploit headers, payload structures and reconnaissance patterns. These infrastructure associations and potential-target lists do not establish successful compromise, exfiltration or common ownership, and some threat-actor connections remain unconfirmed. Organizations should inventory affected applications across cloud and on-premises environments, patch React Server Components and affected frameworks, and restrict internet exposure of development servers. Where patching is unavailable, disable affected server-component functionality if feasible. Investigations should review historical ingress logs for suspicious headers and serialized payloads, unexpected child processes spawned by Node.js, outbound command-and-control connections and unauthorized persistent services; WAF rules and IP blocking are supplementary controls, not substitutes for remediation.

See which actors are running it and whether you're in range.
31 events from the most recent confirmed update back to the earliest known activity.
During February 2–6, 2026, 2.58.56[.]147 became the active Netherlands node in the ILOVEPOOP infrastructure rotation.
Over January 26–February 2, 2026, GreyNoise recorded 1,419,718 exploitation attempts from 1,083 source IPs. Addresses 193.142.147[.]209 and 87.121.84[.]24 accounted for 56%, delivering reverse shells and XMRig payloads respectively.
Niihama recorded 58 DNP3 connections from 87.121.84[.]24 in a 30-minute burst on January 20, 2026. The same node also generated HTTP events across four React2Shell attack waves.
The ILOVEPOOP infrastructure rotated to 195.178.110[.]25 as its primary scanner during January 20–23, 2026.
During January 8–21, 2026, the ILOVEPOOP cluster used 95.214.55[.]246 as a main node and 87.121.84[.]24 as a backup. Researchers linked the cluster through shared exploit headers, multipart payloads, route sweeps, and rotating User-Agents.
Between January 5 and February 6, 2026, Niihama recorded 894 React2Shell/Next.js-related requests from 43 scanner IPs. Activity included static-bundle enumeration, data-route and build-directory probing, and requests for environment files and source maps.
During December 27, 2025–February 4, 2026, Niihama recorded attacks from 669 source IPs that also communicated with two central React2Shell-associated nodes. Activity included SMB, RDP, SSH, and Telnet interactions; a credential-abuse subset generated 25,192 attempts, without establishing common ownership of all sources.
CrowdSec observed more than 10,000 distinct attacking IPs exploiting React2Shell at the December 11 peak, compared with approximately 500 per day in its earlier report. It characterized the increase over several days as roughly 25-fold.
CrowdSec first observed Leakix scanning for React2Shell on December 5, approximately 12 hours after its first attack detection. BinaryEdge and Shadowserver scanning was observed subsequently.
The open-source Nuclei scanner received a working React2Shell detection rule, enabling automated identification of vulnerable applications.
Niihama recorded more than 90 React2Shell exploitation attempts from 85.11.167[.]3 during December 5–8, 2025. Requests targeted multiple login and React/Next.js protocol routes using multipart POST payloads and the Next-Action header.
Expel observed working exploit proof-of-concepts being used against publicly exposed servers by December 5, and GreyNoise first detected exploitation that day. Defused researchers reported mass exploitation with commodity malware and cryptocurrency miners underway by Friday.
AssetNote released React2Shell Scanner to identify unpatched servers. The Raven File subsequently reported that cybercriminals adopted the public tool for target discovery.
CrowdSec’s security team added a virtual patching rule for CVE-2025-55182 to CrowdSec WAF on December 4, 2025, at 11:00 UTC.
AWS reported that China state-nexus groups Earth Lamia and Jackpot Panda exploited React2Shell for initial access within hours of public disclosure.
AWS, Akamai, and Cloudflare implemented mitigations at the time React2Shell was disclosed.
CVE-2025-55182 was disclosed as a critical unauthenticated remote-code-execution vulnerability affecting React Server Components and frameworks including Next.js. Expel and GreyNoise date disclosure to December 3, 2025; the later WhoisXML API report instead gives December 4.
ELLIO reported a custom Go-based Layer 7 DDoS botnet with Cloudflare bypass capabilities in a React2Shell update. The supplied reference does not provide details about victims or deployment.
Niihama captured 195.3.222[.]78 probing an IMAP sensor and sending an HTTP-shaped React2Shell Server Actions payload to a POP3 sensor. Researchers interpreted the payload as an RSC deserialization attempt but did not demonstrate execution through POP3.
WXA IASC identified the ILOVEPOOP React2Shell toolkit and linked 672 exploit attempts across nine scanner nodes over a 30-day observation period. Shared headers, payload structure, route enumeration, and User-Agent rotation supported an inferred common operator, not proof of successful compromise.
The Raven File researcher discovered an exposed directory at 154.61.77.105:8082 containing React2Shell tooling, 35,423 domains, and 596 potential-target URLs. Named organizations included Starbucks, Lululemon, Porsche, and OpenAI, but inclusion did not establish vulnerability or compromise.
CrowdSec reported that early bespoke attacks against banks and healthcare institutions gave way to indiscriminate exploitation of smaller websites and personal blogs. Later exploit kits embedded cryptocurrency miners, with potential botnet recruitment also identified as an objective.
CVE-2025-66478, originally assigned to the Next.js manifestation, was officially rejected as a duplicate. CVE-2025-55182 covers both the React and Next.js manifestations.
Researchers identified a separate script at 209.141.49[.]251 distributing multi-architecture Mirai-variant payloads to enroll machines into a botnet. The malware connected to 205.185.121[.]141:23, and researchers intercepted DDoS commands.
Researchers observed attackers exploiting Next.js servers and distributing XMRig 6.24.0 through sex.sh scripts hosted on compromised sites. Scripts attempted persistence through a system-update-service systemd unit configured to run the miner as root and restart automatically.
Researchers found a React2Shell proof-of-concept at 86.54.42[.]146:8080 targeting a redacted online healthcare organization and requesting a callback after command execution. The same address hosted a MeshAgent server, but the exposed script did not establish that the healthcare organization was compromised.
An exposed directory and shell history at 47.89.245[.]170 revealed React2Shell scanning, Brazilian target lists, and VShell loader infrastructure. The directory also contained a ValleyRAT DLL-hijacking chain using legitimate Bitdefender binaries, not evidence of a Bitdefender breach.
Researchers identified an exposed directory at 180.210.220[.]54 containing Nuclei React2Shell scanning results indicating Vietnamese targeting and Linux VShell loaders. The activity included government and education domains, but earlier university compromises were not established as React2Shell victimization.
Defused researchers observed an associated attacker IP deploying Turnt during exploitation. The tool tunnels interactive command-and-control traffic through legitimate TURN servers, including infrastructure operated by providers such as Zoom.
AWS published indicators connecting React2Shell exploitation to China-nexus threat groups. Defused researchers correlated those indicators with honeypot attacks originating from China, Hong Kong, and Taiwan.
A public Metasploit module for CVE-2025-55182 was published shortly after disclosure, making exploitation through a single HTTP POST request readily accessible.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 112 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
13 references tracked. Mallory keeps watching after this page renders.
main.whoisxmlapi.com
Open sourceplatform.ellio.tech
Open sourcecrowdsec.net
Open sourcetheravenfile.com
Open sourcedefusedcyber.com
Open sourcewiz.io
Open sourcegreynoise.io
Open sourcegreynoise.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.