Tuesday, September 15, 2026

React2Shell Vulnerability Exploited in the Wild, Analysts Warn

React2Shell (CVE-2025-55182) is a critical, pre-auth remote code execution weakness in React Server Components that impacts multiple React versions used across the React 19 ecosystem.

WXA Internet Abuse Signal Collective (WXA IASC) is inaugurating To Cache A Predator, a threat research series that correlates global telemetry, enrichment datasets, and honeypot observations to map attacker infrastructure and tactics tied to CVE-2025-55182, also known as “React2Shell.”

Episode one consolidates indicators of a coherent campaign: fast weaponization after public disclosure, persistent scanning of Next.js paths, and infrastructure concentration around a small set of high-leverage nodes.

Public advisories describe exploitation as possible via crafted network requests that abuse how server-side component payloads are parsed, urging defenders to patch quickly and monitor for exploitation attempts.

Early visibility via Niihama

WXA IASC’s Niihama honeypots observed exploitation attempts within roughly 20 hours of the public disclosure in early December 2025, giving early capture of exploit mechanics and attacker fingerprinting.​

After the initial spike, Niihama continued to log steady React2Shell and Next.js-focused scanning through early February 2026, including probing of /_next/server and large-scale hunting across /_next/static/*.

Across WXA IASC NetFlow-derived telemetry, two Netherlands-hosted nodes stand out as the campaign’s core pivots, each interacting with millions of counterparties over the observation window.

GreyNoise independently reported the same two IPs 193.142.147[.]209 and 87.121.84[.]24 generated 56% of observed React2Shell exploitation traffic in a seven-day slice (Jan 26 to Feb 2, 2026).​

In that GreyNoise window sensors recorded 1,419,718 exploitation attempts targeting CVE-2025-55182, with 193.142.147[.]209 responsible for 488,342 sessions (34%) and 87.121.84[.]24 for 311,484 sessions (22%).​

The “ILOVEPOOP” toolkit

WXA IASC attributes much of the high-fidelity React2Shell activity to a novel, single-operator toolkit dubbed ILOVEPOOP, operating across nine scanner nodes on multiple hosting providers.

The toolkit is fingerprinted by consistent headers and behavior Next-Action: x, X-Nextjs-Request-Id: poop1234, per-attempt X-Nextjs-Html-Request-Id: ilovepoop_*, a repeatable six-path Next.js sweep, and a shared rotation of User-Agents suggesting a reusable exploit stack rather than random probing.

Niihama also recorded follow-on hostile behavior (SMB/RDP/SSH/HTTP attacks and credential abuse) from IPs linked to the same exploit infrastructure, supporting an “early warning” interpretive frame: infrastructure overlap plus behavior overlap indicates risk, not confirmed compromise.

What defenders should do now

  • Patch affected React/Next.js deployments tied to CVE-2025-55182 and validate that mitigations are actually deployed in production.
  • Hunt in reverse proxy, WAF, and app logs for Server Actions–like POST patterns and suspicious Next.js internal headers (including the ILOVEPOOP canary IDs), then pivot to source IP, ASN, and hosting provider patterns.
  • Treat these findings as evidence of hostile activity and scanning pressure; prioritize exposure reduction, least privilege, and rapid containment plans for internet-facing systems.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor

China-linked threat actors tracked as UNC3569 have exploited a...

Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users

A Casbaneiro banking Trojan campaign targeting users across Latin...

AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process

A five-stage AsyncRAT campaign that chains a socially engineered...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

Related Articles

Recent News