React2Shell Exploited for Crypto Mining and Malware Attacks

Critical React2Shell Vulnerability in React Server Components Enables Remote Code Execution and Widespread Malware Deployment

  • React2Shell exploit leverages a critical security flaw in React Server Components (RSC) for remote code execution and Malware deployment.
  • Attackers distribute diverse malware, including the PeerBlight Linux backdoor, CowTunnel proxy, and ZinFoq post-exploitation tool.
  • Tens of thousands of vulnerable instances remain globally, with notable concentrations in the U.S., Germany, France, and India.
  • Automated attacks target various sectors, mainly construction and entertainment, often using publicly available tools to locate vulnerable Next.js servers.
  • Immediate updates to affected React Server Component packages are strongly advised due to the high risk of exploitation.

React2Shell continues to see heavy use by cybercriminals exploiting a severe security vulnerability in React Server Components (RSC). As disclosed in recent reports from Huntress, threat actors use this flaw, tracked as CVE-2025-55182, to perform unauthenticated remote code execution. Since early December 2025, multiple industries, especially construction and entertainment, have been targeted worldwide.

- Advertisement -

Initial attacks were observed on December 4, 2025, where attackers exploited vulnerable Next.js applications to deliver a cryptocurrency miner and the Linux backdoor PeerBlight. These campaigns involve automated tools that indiscriminately deploy Linux and Windows payloads, including attempts to execute discovery commands and fetch malicious files from command-and-control (C2) servers.

Among the malware payloads identified are:

sex.sh: A Bash script that downloads the XMRig cryptocurrency miner version 6.24.0 directly from GitHub.

PeerBlight: A stealthy Linux backdoor sharing code with older malware families RotaJakiro and Pink. It persists by installing a systemd service and disguises itself as the “ksoftirqd” daemon process.

- Advertisement -

CowTunnel: A reverse proxy creating outbound connections to attacker-controlled Fast Reverse Proxy servers, bypassing firewall restrictions.

ZinFoq: A Go-based Linux ELF implant enabling interactive shells, file manipulation, network pivoting, and timestomping.

Other scripts such as d5.sh and fn22.sh deploy or update the Sliver C2 framework, while wocaosinm.sh is a variant of the Kaiji DDoS malware with added persistence and evasion.

The PeerBlight backdoor communicates with a hardcoded C2 address (“185.247.224[.]41:8443”) to perform file operations, spawn reverse shells, and self-update. It also uses a domain generation algorithm (DGA) combined with the BitTorrent Distributed Hash Table (DHT) network to discover other infected nodes. According to researchers, infected bots register with DHT node IDs starting with the prefix “LOLlolLOL” to identify fellow bots or attacker nodes.

Similarly, ZinFoq connects to its C2 server to execute commands through “/bin/bash,” manage files, download additional payloads, and establish reverse shells. It erases bash history for stealth and impersonates 44 legitimate Linux system services to avoid detection.

Due to the potential ease of exploitation and high impact of this vulnerability, organizations using react-server-dom-webpack, react-server-dom-parcel, or react-server-dom-turbopack are urged to apply updates immediately.

The Shadowserver Foundation reports over 165,000 IPs and 644,000 domains Hosting vulnerable code as of December 8, 2025. More than 99,200 instances are in the United States, followed by Germany (14,100), France (6,400), and India (4,500). The volume of exposed servers highlights a significant ongoing risk related to this flaw.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Quantum Solutions posts $4.71M unrealized ETH holdings loss.

Quantum Solutions bought about $20.6 million of Ethereum, holding roughly 5,030 ETH on its...

Phishing losses fall 83% to $83.85M as attacks shift in 2025

Annual phishing losses tied to wallet drainers fell 83% to $83.9 million in 2025.The...

XRP Reality Check: 70% Expect Token to Remain Below $2 in Q1

About 70% of respondents expect XRP to remain under $2 in the near term.Nick...

Bitcoin Turns 17; Spot ETFs Suffer Heaviest Weekly Losses…

Bitcoin marked its 17th anniversary as it remains embedded in global markets.U.S. spot Bitcoin...

BRICS Unit’s Gold Currency Faces Coordination, Tech Failures

BRICS members disagree on a common currency and have shown mixed political support.Technical and...
- Advertisement -

Must Read

Top 5 Testing Tools For Blockchain Applications in 2022

Blockchain apps have been adopted popularly by some prominent industries due to its being a decentralized-designed technology. Furthermore, these apps eliminate the risks that...
Bitcoin (BTC) $ 89,932.00 0.75%
Ethereum (ETH) $ 3,100.79 1.75%
XRP (XRP) $ 2.00 5.72%
Bittensor (TAO) $ 246.39 1.11%
Polkadot (DOT) $ 2.12 6.19%
Cardano (ADA) $ 0.38755 6.29%
Chainlink (LINK) $ 13.11 0.74%
Hyperliquid (HYPE) $ 24.62 0.19%
Monero (XMR) $ 430.94 3.37%
Hedera (HBAR) $ 0.119245 0.27%
Toncoin (TON) $ 1.80 4.27%