BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

React2Shell Exploited for Crypto Mining and Malware Attacks

Critical React2Shell Vulnerability in React Server Components Enables Remote Code Execution and Widespread Malware Deployment

  • React2Shell exploit leverages a critical security flaw in React Server Components (RSC) for remote code execution and Malware deployment.
  • Attackers distribute diverse malware, including the PeerBlight Linux backdoor, CowTunnel proxy, and ZinFoq post-exploitation tool.
  • Tens of thousands of vulnerable instances remain globally, with notable concentrations in the U.S., Germany, France, and India.
  • Automated attacks target various sectors, mainly construction and entertainment, often using publicly available tools to locate vulnerable Next.js servers.
  • Immediate updates to affected React Server Component packages are strongly advised due to the high risk of exploitation.

React2Shell continues to see heavy use by cybercriminals exploiting a severe security vulnerability in React Server Components (RSC). As disclosed in recent reports from Huntress, threat actors use this flaw, tracked as CVE-2025-55182, to perform unauthenticated remote code execution. Since early December 2025, multiple industries, especially construction and entertainment, have been targeted worldwide.

- Advertisement -

Initial attacks were observed on December 4, 2025, where attackers exploited vulnerable Next.js applications to deliver a cryptocurrency miner and the Linux backdoor PeerBlight. These campaigns involve automated tools that indiscriminately deploy Linux and Windows payloads, including attempts to execute discovery commands and fetch malicious files from command-and-control (C2) servers.

Among the malware payloads identified are:

sex.sh: A Bash script that downloads the XMRig cryptocurrency miner version 6.24.0 directly from GitHub.

PeerBlight: A stealthy Linux backdoor sharing code with older malware families RotaJakiro and Pink. It persists by installing a systemd service and disguises itself as the “ksoftirqd” daemon process.

- Advertisement -

CowTunnel: A reverse proxy creating outbound connections to attacker-controlled Fast Reverse Proxy servers, bypassing firewall restrictions.

ZinFoq: A Go-based Linux ELF implant enabling interactive shells, file manipulation, network pivoting, and timestomping.

Other scripts such as d5.sh and fn22.sh deploy or update the Sliver C2 framework, while wocaosinm.sh is a variant of the Kaiji DDoS malware with added persistence and evasion.

The PeerBlight backdoor communicates with a hardcoded C2 address (“185.247.224[.]41:8443”) to perform file operations, spawn reverse shells, and self-update. It also uses a domain generation algorithm (DGA) combined with the BitTorrent Distributed Hash Table (DHT) network to discover other infected nodes. According to researchers, infected bots register with DHT node IDs starting with the prefix “LOLlolLOL” to identify fellow bots or attacker nodes.

Similarly, ZinFoq connects to its C2 server to execute commands through “/bin/bash,” manage files, download additional payloads, and establish reverse shells. It erases bash history for stealth and impersonates 44 legitimate Linux system services to avoid detection.

Due to the potential ease of exploitation and high impact of this vulnerability, organizations using react-server-dom-webpack, react-server-dom-parcel, or react-server-dom-turbopack are urged to apply updates immediately.

The Shadowserver Foundation reports over 165,000 IPs and 644,000 domains Hosting vulnerable code as of December 8, 2025. More than 99,200 instances are in the United States, followed by Germany (14,100), France (6,400), and India (4,500). The volume of exposed servers highlights a significant ongoing risk related to this flaw.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

BitMEX Analyst: Bond Yield Surge Fuels Bitcoin Supercycle

A Bitmex analyst argues surging sovereign bond yields will force a "structural" shift, creating...

U.S. Lawmakers Push “Fort Knox” Bitcoin Reserve Plan

The ARMA Act proposes creating a U.S. Strategic Bitcoin Reserve, backed by 5% of...

The Secret Behind Shiba Inu’s Meteoric 2021 Rise

Shiba Inu's 2021 rally was fueled by a massive token burn by Ethereum co-founder...

npm Staged Publishing Requires Human Approval

GitHub has introduced mandatory two-factor approval for npm package releases to combat software supply...

Hayes Picks Hyperliquid, Slams Other Altcoins

Arthur Hayes predicts a global "Hunger Games of debt issuance" will drive Bitcoin to...

Must Read

Top 8 Books Every Beginner Should Read About Cryptocurrency

Cryptocurrency and blockchain technology are filled with technical terms that beginners find challenging to understand. One of the best ways to learn about cryptocurrency...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading