React2Shell Exploited for Crypto Mining and Malware Attacks

Critical React2Shell Vulnerability in React Server Components Enables Remote Code Execution and Widespread Malware Deployment

  • React2Shell exploit leverages a critical security flaw in React Server Components (RSC) for remote code execution and Malware deployment.
  • Attackers distribute diverse malware, including the PeerBlight Linux backdoor, CowTunnel proxy, and ZinFoq post-exploitation tool.
  • Tens of thousands of vulnerable instances remain globally, with notable concentrations in the U.S., Germany, France, and India.
  • Automated attacks target various sectors, mainly construction and entertainment, often using publicly available tools to locate vulnerable Next.js servers.
  • Immediate updates to affected React Server Component packages are strongly advised due to the high risk of exploitation.

React2Shell continues to see heavy use by cybercriminals exploiting a severe security vulnerability in React Server Components (RSC). As disclosed in recent reports from Huntress, threat actors use this flaw, tracked as CVE-2025-55182, to perform unauthenticated remote code execution. Since early December 2025, multiple industries, especially construction and entertainment, have been targeted worldwide.

- Advertisement -

Initial attacks were observed on December 4, 2025, where attackers exploited vulnerable Next.js applications to deliver a cryptocurrency miner and the Linux backdoor PeerBlight. These campaigns involve automated tools that indiscriminately deploy Linux and Windows payloads, including attempts to execute discovery commands and fetch malicious files from command-and-control (C2) servers.

Among the malware payloads identified are:

sex.sh: A Bash script that downloads the XMRig cryptocurrency miner version 6.24.0 directly from GitHub.

PeerBlight: A stealthy Linux backdoor sharing code with older malware families RotaJakiro and Pink. It persists by installing a systemd service and disguises itself as the “ksoftirqd” daemon process.

- Advertisement -

CowTunnel: A reverse proxy creating outbound connections to attacker-controlled Fast Reverse Proxy servers, bypassing firewall restrictions.

ZinFoq: A Go-based Linux ELF implant enabling interactive shells, file manipulation, network pivoting, and timestomping.

Other scripts such as d5.sh and fn22.sh deploy or update the Sliver C2 framework, while wocaosinm.sh is a variant of the Kaiji DDoS malware with added persistence and evasion.

The PeerBlight backdoor communicates with a hardcoded C2 address (“185.247.224[.]41:8443”) to perform file operations, spawn reverse shells, and self-update. It also uses a domain generation algorithm (DGA) combined with the BitTorrent Distributed Hash Table (DHT) network to discover other infected nodes. According to researchers, infected bots register with DHT node IDs starting with the prefix “LOLlolLOL” to identify fellow bots or attacker nodes.

Similarly, ZinFoq connects to its C2 server to execute commands through “/bin/bash,” manage files, download additional payloads, and establish reverse shells. It erases bash history for stealth and impersonates 44 legitimate Linux system services to avoid detection.

Due to the potential ease of exploitation and high impact of this vulnerability, organizations using react-server-dom-webpack, react-server-dom-parcel, or react-server-dom-turbopack are urged to apply updates immediately.

The Shadowserver Foundation reports over 165,000 IPs and 644,000 domains Hosting vulnerable code as of December 8, 2025. More than 99,200 instances are in the United States, followed by Germany (14,100), France (6,400), and India (4,500). The volume of exposed servers highlights a significant ongoing risk related to this flaw.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

MSTR Jumps As MSCI Delays Exclusion of Crypto Treasury Firms

MSTR shares rose nearly 6% in after-hours trading after MSCI said it would not...

Tesla Shares Slip After USPTO Blocks Cybercab, Robotaxi Name

Tesla shares dipped after the United States Patent and Trademark Office denied trademark applications...

Elon Musk’s xAI Raises $20B; Valuation Still Undisclosed Now

xAI raised $20 billion in an upsized Series E, surpassing a prior $15 billion...

Riot sells 2,201 BTC for $200M to fund AI data center build.

Riot Platforms sold 2,201 BTC across November and December, raising nearly $200 million in...

Aave v4 and Lido v3 Spark Major DeFi Upgrades, 2026 Outlook!

Major DeFi protocols plan substantive upgrades in early 2026.Aave is preparing a new architecture...
- Advertisement -

Must Read

18 Countries With No Privacy Laws According To UN (List)

Privacy laws are legal frameworks designed to protect personal data from unauthorized access, misuse, or disclosure.Lack of privacy laws can lead to misuse of...
Bitcoin (BTC) $ 93,126.00 0.55%
Ethereum (ETH) $ 3,274.42 2.13%
XRP (XRP) $ 2.31 1.51%
Bittensor (TAO) $ 288.55 8.07%
Polkadot (DOT) $ 2.21 1.17%
Cardano (ADA) $ 0.416318 0.53%
Chainlink (LINK) $ 13.91 1.71%
Hyperliquid (HYPE) $ 27.99 5.77%
Monero (XMR) $ 442.28 0.54%
Hedera (HBAR) $ 0.127605 2.29%
Toncoin (TON) $ 1.89 0.36%