LIVE NEWS
  • U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals
  • Ukraine Splits up Weapons Making, Warns Europe Must Do the Same
  • Bookshelf: the untold story of a UN secretary-general
  • Lilly, Novo, Pfizer look to new weight loss drugs
  • From protest to silence: China’s long game in Zambia
  • ‘This might be the point of no return’: Experts on the current measles outbreak and where we go from here
  • 5 killed when Indian Air Force transport aircraft crashes in Assam
  • Legacy sportsbooks are chasing prediction markets that already trade billions each month
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Chinese Hackers Exploiting React2Shell Vulnerability
Cybersecurity

Chinese Hackers Exploiting React2Shell Vulnerability

primereportsBy primereportsDecember 5, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Chinese Hackers Exploiting React2Shell Vulnerability
Share
Facebook Twitter LinkedIn Pinterest Email


Threat actors have apparently started exploiting the newly disclosed React vulnerability tracked as React2Shell and CVE-2025-55182.

The critical vulnerability can be exploited using specially crafted HTTP requests for unauthenticated remote code execution on affected servers. It was reported to React maintainer Meta on November 29 by researcher Lachlan Davidson, and it was patched on December 3.

React2Shell may impact many systems considering that React, an open source JavaScript library designed for creating application user interfaces, powers millions of websites and its associated NPM package has millions of weekly downloads. Cloud security giant Wiz reported that 39% of cloud environments contain vulnerable React instances. 

Davidson has set up a dedicated React2Shell website, but has not made public the technical details of the vulnerability. However, threat actors and researchers have been reverse-engineering the patches.

Several proof-of-concept (PoC) exploits were made public shortly after React2Shell’s disclosure, but they turned out to be fake. However, there appears to be at least one public PoC exploit that works.

Unsurprisingly, exploitation attempts have also been seen. AWS reported late on Thursday that its threat intelligence teams started seeing CVE-2025-55182 exploitation attempts by China-linked threat actors within hours of public disclosure. 

AWS noted that while precise attribution is challenging due to threat actors sharing attack infrastructure, it believes attack attempts have been conducted by the groups known as Earth Lamia and Jackpot Panda. 

Earth Lamia has been active since at least 2023, targeting a wide range of industries in Latin America, the Middle East, and Southeast Asia. The threat actor has been observed exploiting several vulnerabilities in its attacks.

Advertisement. Scroll to continue reading.

Jackpot Panda has been around since 2020, conducting cyberespionage operations in Asia.

“Threat actors are using both automated scanning tools and individual PoC exploits,” AWS said.

Dan Andrew, head of security at Intruder, told SecurityWeek that they have also witnessed exploitation activity for React2Shell, but has not shared information on who may be behind the attacks.

Scanning and fake PoC exploits

CVE-2025-55182 is being added to vulnerability scanners and offensive security tools, which could lead to even more widespread exploitation attempts.

On the other hand, security researcher Kevin Beaumont pointed out that the vulnerability only impacts React version 19, specifically instances that use a relatively new server feature. 

As Beaumont pointed out, some of these exploitation attempts are leveraging fake PoCs.

Chinese Hackers Exploiting React2Shell Vulnerability

AWS confirmed that some threat actors are attempting to use the fake PoCs, which don’t work in real-world scenarios, indicating that they are desperately trying to exploit the vulnerability as quickly as possible.

However, AWS has also seen threat actors systematically troubleshooting their exploitation attempts to get them to work.

“This behavior demonstrates that threat actors aren’t just running automated scans, but are actively debugging and refining their exploitation techniques against live targets,” AWS explained. 

The cloud company has made available indicators of compromise (IoCs) to help organizations detect potential exploitation attempts.

Related: Microsoft Silently Mitigated Exploited LNK Vulnerability

Related: Reporters Without Borders Targeted by Russian Hackers

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAWS Graviton5 Strikes A Different Balance For Server CPUs
Next Article Merz seeks to lock in pension bill majority – DW – 12/05/2025
primereports
  • Website

Related Posts

Cybersecurity

U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals

June 13, 2026
Cybersecurity

Who Runs the Ransomware Group ‘The Gentlemen?’ – Krebs on Security

June 12, 2026
Cybersecurity

In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine

June 12, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals
  • Ukraine Splits up Weapons Making, Warns Europe Must Do the Same
  • Bookshelf: the untold story of a UN secretary-general
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.