React2Shell CVE-2025-55182 — Multiple Threat Actors Actively Exploiting React Server Components RCE (CVSS 10.0) — Threadlinqs Intelligence
As of 2026-07-19, React2Shell CVE-2025-55182 — Multiple Threat Actors Actively Exploiting React Server Components RCE (CVSS 10.0) is a critical-severity vulnerability threat attributed to Earth Lamia (China, Iran), tracked by Threadlinqs Intelligence with 12 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 115 indicators of compromise.
Threat ID: TL-2026-0080 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-07-19 · 2 updates · revalidated 2× · latest source
Attribution: Earth Lamia · China, Iran · ESPIONAGE
CVE-2025-55182 ('React2Shell') is a CVSS 10.0 unauthenticated remote code execution vulnerability in React Server Components (RSC) affecting packages react-server-dom-webpack, react-server-dom-parcel,
**Vulnerability Details:**
CVE-2025-55182 is an unauthenticated remote code execution (RCE) vulnerability in React Server Components (RSC). The flaw allows an unauthenticated attacker to send a SINGLE HTTP request that executes arbitrary code with the privileges of the user running the affected web server process. CVSS v3.x score: 10.0 (maximum). CVSS v4: 9.3. The vulnerability exists in RSC packages used by popular frameworks like Next.js, making the exposed attack surface enormous.
Vulnerable packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0, 19.1.0, 19.1.1, 19.2.0). The mere presence of vulnerable packages on systems is often enough to permit exploitation — multiple valid payload formats and techniques exist. A separate CVE for Next.js (CVE-2025-66478) was issued but marked as a duplicate of CVE-2025-55182.
**Attack Timeline (JPCERT/CC documented case):**
- Dec 3, 2025: CVE-2025-55182 disclosed
- Dec 5, 15:52 JST: First coin miner (sex.sh, xmrig) installed — 48 hours after disclosure
- Dec 6, 07:28: Second coin miner wave
- Dec 6, 09:53-11:00: HISONIC backdoor (javax) installed — attributed to UNC6603
- Dec 6, 15:00: Global Socket (gsocket as npm-cli) installed with hourly cron — backdoor over port 53 (DNS)
- Dec 6, 19:31: SNOWLIGHT downloader (javas) + CrossC2 RAT (rsyslo) installed — attributed to UNC5174
- Dec 7, 12:24: Third coin miner wave
- Dec 7, 16:51: Cron modified — /tmp/kernal (disguised as kernel) executing every minute
- Dec 7, 19:46: Website defacement with CVE warning in 4 languages
- Dec 7, 22:15: Incident discovered via user report
- Dec 5-7: 100+ unique scanning IPs observed targeting the server
**Threat Actor Attribution (GTIG/Mandiant):**
1. **UNC6600** (China-nexus espionage): Deployed MINOCAT tunneler. Creates hidden .systemd-utils directory, establishes persistence via cron + systemd + .bashrc injection. MINOCAT is 64-bit ELF with embedded Fast Reverse Proxy (FRP) client.
2. **UNC6586** (China-nexus, suspected): Deployed SNOWLIGHT downloader fetching from reactcdn.windowserrorapis[.]com. SNOWLIGHT is VSHELL component — Go-based multi-platform backdoor.
3. **UNC6588** (China-nexus): Deployed COMPOOD backdoor masquerading as /tmp/vim, then executing as polkitd. Historically linked to China-nexus espionage.
4. **UNC6603** (China-nexus): Deployed updated HISONIC backdoor — Go-based implant using Cloudflare Pages and GitLab for encrypted config retrieval. Targeting AWS and Alibaba Cloud in APAC.
5. **UNC6595** (China-nexus): Deployed ANGRYREBEL.LINUX masquerading as sshd in /etc/. Uses timestomping and shell history clearing for anti-forensics.
6. **UNC5174** (China-nexus, MSS-affiliated): Previously known for SNOWLIGHT. IIJ documented Windows variant in Oct 2025 targeting Japanese organizations.
7. **Financially motivated actors**: XMRig cryptomining, the FIRST to exploit (within 48 hours).
8. **Iran-nexus actors**: GTIG observed exploitation but details not published.
9. **Website defacers**: Warning messages in 4 languages urging patching.
**Additional Context:**
AWS reported that China-nexus groups Earth Lamia (tracked as UNC5454 by GTIG) and Jackpot Panda are also exploiting CVE-2025-55182. Underground forums are actively sharing scanning tools, PoC code, and exploitation experiences. Many non-functional and malicious fake PoCs were distributed, some containing malware targeting security researchers. Three additional CVEs followed: CVE-2025-55183 (info disclosure), CVE-2025-55184 (DoS), CVE-2025-67779 (DoS, incomplete patch for 55184).
Weaknesses (CWE)
CWE-94, CWE-502, CWE-20, CWE-749, CWE-400
Target sectors: Technology, Government, Cloud Infrastructure, Education, Financial Services, Healthcare, Critical Infrastructure
Target regions: Global, Asia Pacific, Japan, North America, Europe
Detections & IOCs
As of 2026-07-27, this threat has 12 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 115 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2025-55182, CVE-2025-55183, CVE-2025-55184, CVE-2025-67779, CVE-2025-66478, T1190, T1059, T1059, T1053, T1543, T1546, T1505, T1036, T1070, T1070