@hakluke@xnl_h4ck3r@_jensec 6️⃣ React2shell-scanner
React2shell-scanner by @assetnote is a Python CLI tool that detects CVE-2025-55182 & CVE-2025-66478 in Next.js apps, with WAF bypass support built in! 😎
🔗 https://github.com/assetnote/react2shell-scanner https://t.co/20y1ARF70u
Post summary
The tweet announces a Python CLI tool that scans Next.js applications for CVE‑2025‑55182 and CVE‑2025‑66478, offering built‑in WAF bypass, but provides no exploit, patch, or technical vulnerability details.
High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478) https://slcyber.io/research-center/high-fidelity-detection-mechanism-for-rsc-next-js-rce-cve-2025-55182-cve-2025-66478/
Post summary
The text announces a detection mechanism for the RSC/Next.js remote code execution vulnerabilities CVE-2025-55182 and CVE-2025-66478, but it does not provide exploit details, patches, or evidence of active exploitation.
The tweet simply links to a Palo Alto Networks article about two CVEs, offering no direct information on exploitation, patches, or technical specifics.
@_adembilican_@coolifyio@Hetzner_Online All the kudos the the German Federal Office for Information Security for letting you know you are vulnerable and you should fix the issue :). I received such emails when NextJS was impacted by CVE-2025-66478 a few months ago :)
Post summary
The tweet references CVE‑2025‑66478 and a call to remediate the issue, but omits technical details, PoC, or evidence of exploitation.
@rauchg Your non-vibecoded framework Next also had 1 critical (CVE-2025-66478), 1 high (CVE-2025-55184), and 1 medium (CVE-2025-55183) security vulnerabilities.
Post summary
The tweet announces that the framework Next contains three vulnerabilities—one critical, one high, and one medium—without providing further technical details or mitigation steps.
Waiting gracefully for OKC belt tonight, my next js project decided it was the perfect time to try me. Runtime logs showed that it was passing a n attackers input int child_process.exec.
Confirmed I was being hit by CVE-2025-66478.
exec call only failed because I was using..
Post summary
The author confirms active exploitation of CVE-2025-66478 via child_process.exec, providing minimal technical detail and no patch information.
Interesting timing to lecture about security.
In the last 3 months alone, your stack shipped:
• CVE-2025-66478 — RCE, CVSS 10.0. Exploited in the wild by nation-state actors.
• CVE-2025-55184 — DoS, CVSS 7.5. Initial patch was incomplete, required a 2nd fix.
Post summary
The post highlights two recent CVEs, noting that CVE‑2025‑66478 (an RCE with CVSS 10.0) has been exploited in the wild by nation‑state actors, while CVE‑2025‑55184 (a DoS with CVSS 7.5) suffered an incomplete initial patch requiring a second fix.
React2shell: CVE-2025-55182 Critical RCE Vulnerability in React and Next.js
https://api.cyfluencer.com/s/react2shell-cve-2025-55182-cve-2025-66478-critical-rce-vulnerabilities-in-react-and-next-js-25541/1
Post summary
The text announces a critical RCE vulnerability (CVE-2025-55182) affecting React and Next.js, but provides no details on PoC, exploitation, or patches.
Securing the Modern Web - React and Next.js Applications [ React2Shell CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) ]
https://medium.com/@mdsiaofficial/securing-the-modern-web-react-and-next-js-ff71015aa1c8
Post summary
The text references CVE-2025-55182 and CVE-2025-66478 with a Medium article link, but provides no further details on exploitation, mitigation, or technical specifics.
📌 High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)
🔹 Détection automatique des CVE
🔹 Analyse des composants React
🔗 https://github.com/assetnote/react2shell-scanner #Python
Post summary
The post introduces a new detection scanner for Next.js RCE CVEs (CVE‑2025‑55182 & CVE‑2025‑66478) and provides a GitHub link for the tool.
🚨 Threat Alert: Next.js Hosts Compromised via React2Shell (CVE-2025-55182) — Automated Credential Harvesting (UAT-10608)
📅 Date: 2026-04-03
📆 Timeline: 2025-12-03: CVE-2025-55182 disclosed. 2025-12-05 onward: in‑the‑wild exploitation. Dec 2025: multiple vendors publish telemetry. 2026-04-03: Cisco Talos reports UAT-10608 — 766 hosts observed in 24h.
📍 Location: Global (web applications worldwide)
📌 Attribution: Primary cluster: UAT-10608 (Cisco Talos). Other clusters observed by Google, Microsoft, AWS (UNC6600/6586/6588/6603/6595). Multiple opportunistic criminal and some nation‑nexus activity; no definitive public state attribution.
📝 Summary:
Cisco Talos reports an automated credential‑theft campaign (UAT-10608) exploiting React2Shell (CVE-2025-55182) in React Server Components/Next.js. Attackers used unauthenticated RCE to deploy web shells and scripts that harvested DB credentials, SSH keys, cloud tokens, GitHub tokens and API keys from internet‑facing Next.js hosts. Hundreds of hosts were compromised rapidly after disclosure.
⚔️ Attack Details:
- Attack Type: Credential theft via unauthenticated remote code execution (React2Shell) with post-exploit web shells, downloaders, and backdoors
- Target: Internet-facing Next.js applications / React Server Components (over 700 compromised servers; Cisco Talos: 766 hosts recorded by NEXUS Listener)
📈 Impact:
>700 servers compromised; widespread theft of database credentials, private SSH keys, cloud credentials (AWS/Azure/GCP), GitHub tokens and API keys; risk of account takeover, lateral movement, persistence, data exfiltration, and supply‑chain/code integrity abuse. Operational scale: 766 hosts observed in 24 hours by Cisco Talos. No public quantified financial loss reported.
🔗 Related Resources:
- https://cybersecuritynews.com/700-next-js-hosts-exploited/
- https://blog.talosintelligence.com/uat-10608-inside-a-large-scale-automated-credential-harvesting-operation-targeting-web-applications/
- https://cloud.google.com/blog/topics/threat-intelligence/threat-actors-exploit-react2shell-cve-2025-55182
- https://nextjs.org/blog/CVE-2025-66478
- https://www.microsoft.com/en-us/security/blog/2025/12/15/defending-against-the-cve-2025-55182-react2shell-vulnerability-in-react-server-components/
🛡️ Recommended Actions:
- Patch immediately: upgrade React / React Server Components and Next.js to vendor‑patched versions.
- Rotate all secrets, API keys, and tokens after patching and redeploy.
- Deploy WAF rules (Cloud Armor / Azure WAF / vendor rules) as temporary compensating control.
- Restrict cloud metadata access (IMDS) and apply least privilege for instance roles.
- Enable EDR and hunt for indicators: suspicious node/next-server child processes launching curl/wget, hidden dirs (e.g., $HOME/.systemd-utils), new cron/systemd services, modifications to authorized_keys.
- Revoke and rebuild suspected‑exfiltrated credentials (SSH keys, cloud keys, GitHub tokens).
- Isolate and perform incident response on compromised hosts; collect forensic artifacts and scan estate for vulnerable package versions.
- Implement ongoing secrets scanning, credential hygiene, and vulnerability management.
🫨 Attack Vectors:
- T1190 - Exploit Public-Facing Application (React2Shell / CVE-2025-55182)
- T1059 - Command and Scripting Interpreter (bash, curl/wget execution to fetch payloads)
- T1505.003 - Server Software Component: Web Shell (in-memory web shells / Next.js web shell deployments)
- T1078 - Valid Accounts (use and abuse of stolen credentials/SSH keys)
- T1555 - Credentials from Password Stores/Files (secret discovery tools and scripts: TruffleHog, Gitleaks, custom stealers)
- T1086 - PowerShell (encoded/obfuscated commands observed in post-exploit activity)
🏷 Tags: #credential-theft #Next.js #React2Shell#CVE-2025-55182 #web-RCE #UAT-10608 #CiscoTalos#Cybersecurity
Post summary
The post reports that CVE‑2025‑55182 is actively exploited worldwide via an unauthenticated RCE in React Server Components/Next.js, with large‑scale credential theft, and recommends immediate patching and mitigation steps.
🚨 Threat Alert: EtherRAT / EtherHiding Blockchain C2 Malware Campaign
📅 Date: 2026-04-01
📆 Timeline: 2025-12-05 to 2025-12-12: React2Shell (CVE-2025-55182) disclosed and early exploitation observed; 2025-12-08: Sysdig published detailed EtherRAT analysis; Dec 2025–Mar 2026: multiple vendor observations and telemetry (Unit42, eSentire); 2026-03: eSentire TRU reported a retail intrusion with EtherRAT and EtherHiding C2; 2026-04-01: GBHackers and others reported on ongoing activity.
📍 Location: Global (internet-exposed React/Next.js servers; observed across multiple industries)
📌 Attribution: Reported and analyzed by Sysdig and Unit42; operational overlaps with DPRK-associated "Contagious Interview" activity and UNC5342 reported by multiple vendors (medium confidence). NOT confirmed with 100% confidence.
📝 Summary:
EtherRAT is a Node.js backdoor that uses an Ethereum-based technique called "EtherHiding" to store and rotate command-and-control (C2) endpoints in smart contract state, making takedown and detection difficult. It is multi-stage (downloader → Node.js runtime fetch → encrypted dropper → implant), supports arbitrary JavaScript execution via an AsyncFunction/eval-style construct, downloads its own Node runtime, and implements multiple persistence mechanisms (systemd user service, XDG autostart, cron, .bashrc/.profile). Public reporting (Sysdig, Unit42, eSentire) links EtherRAT operationally to React2Shell (CVE-2025-55182) exploitation and shows overlaps with DPRK-associated activity (Contagious Interview / UNC5342), though final attribution is not confirmed.
⚔️ Attack Details:
- Attack Type: Backdoor / Blockchain-based Command-and-Control (C2) Malware
- Target: Internet-facing servers and hosts running Node.js workloads and React/Next.js RSC endpoints (observed in retail, business services, software and finance environments); both Linux and Windows hosts where Node.js can run
📈 Impact:
Persistent remote access and full remote code execution on compromised hosts; covert, resilient C2 (blockchain-resolved) resistant to classic takedowns; potential data theft, lateral movement and deployment of secondary payloads; remediation and incident response costs can be substantial (varies by victim — from tens of thousands to potentially $1M+ for large breaches). Exact data loss and monetary impact not publicly disclosed.
🔗 Related Resources:
- https://www.sysdig.com/blog/etherrat-dprk-uses-novel-ethereum-implant-in-react2shell-attacks
- https://gbhackers.com/ethereum-based-etherrat/
- https://unit42.paloaltonetworks.com/cve-2025-55182-react-and-cve-2025-66478-next/
- https://www.esentire.com/blog/etherrat-sys-info-module-c2-on-ethereum-etherhiding-target-selection-cdn-like-beacons
- https://cloud.google.com/blog/topics/threat-intelligence/dprk-adopts-etherhiding
🛡️ Recommended Actions:
- Patch React/Next.js and affected RSC components (apply vendor patches for CVE-2025-55182).
- Isolate and forensically image suspected hosts; rebuild from known-good images where compromise is confirmed.
- Rotate credentials and secrets accessible from compromised hosts.
- Deploy EDR/NGAV with Node.js/JS runtime behavioral rules; enable runtime protection (e.g., Falco/Sysdig rules).
- Monitor for outbound Ethereum RPC calls (eth_call) and unusual connections to public RPC endpoints; block unnecessary outbound access to public Ethereum RPC providers.
- Hunt for randomized GET patterns (/api/{random}/{bot_id}/{random}.{ext}) and X-Bot-Server header; look for randomized $HOME/.local/share/ directories, random-named systemd user services, XDG autostart and cron @reboot entries, and unexpected nodejs downloads.
- Apply egress filtering and WAF rules to detect/block React2Shell exploitation; block known staging IPs/URLs.
- Remove persistence artifacts, update detection content and TI feeds, and engage IR/MDR if required.
🫨 Attack Vectors:
- T1190 - Exploit Public-Facing Application: React2Shell (CVE-2025-55182) used as initial access in multiple reports.
- T1105 - Ingress Tool Transfer: Download of Node.js runtime and staged payloads from attacker-controlled staging servers (e.g., http://193.24.123.68:3001).
- T1059.007 - Command and Scripting Interpreter: JavaScript/Node.js: Execution of arbitrary JavaScript via AsyncFunction/eval-like constructs; operators can run arbitrary Node.js modules.
- T1071 - Application Layer Protocol (HTTPS): C2 polling over HTTPS, mimicking CDN asset requests (.png/.css/.ico) to blend in with normal traffic.
- T1027 - Obfuscated Files or Information: Use of JavaScript obfuscator (http://Obfuscator.io) and re-obfuscation/rewrite behavior from C2.
- T1547.001 - Boot or Autostart Initialization: Systemd/User Service: Persistence via randomly-named systemd user services, XDG autostart, cron @reboot entries, and shell config injection.
- Custom - Blockchain-based C2 (EtherHiding): Use of Ethereum smart contract state and transactions to store/rotate C2 endpoints; consensus across multiple public RPC endpoints for resilience.
🏷 Tags: #malware#backdoor#EtherRAT#EtherHiding#Ethereum#blockchain#Node.js #C2#UNC5342#ContagiousInterview#DPRK#Cybersecurity
Post summary
The text reports that the EtherRAT/ EtherHiding malware campaign has been actively exploiting the React/Next.js CVE‑2025‑55182 in the wild, with multiple vendor confirmations and ongoing activity, and provides accompanying mitigation advice.
Yesterday, the CBN issued an advisory, based on guidance from ngCERT, warning financial institutions about critical vulnerabilities (CVE-2025-55182 and CVE-2025-66478) in React Server Components (versions 19.0 to 19.2) and Next.js (versions 15 to 16) that could allow unauthenticated remote code execution due to insecure deserialization in the RSC “Flight” protocol.
These flaws pose serious risks including full system compromise, data theft, ransomware attacks, and operational disruption, especially as active exploitation attempts and proof-of-concept tools already exist. Institutions are therefore required to urgently identify affected systems, apply patches or mitigations, enhance monitoring, conduct forensic assessments, notify relevant vendors, and promptly report any suspected or confirmed incidents to the CBN.
Post summary
The advisory highlights critical RSC/Next.js vulnerabilities that support unauthenticated remote code execution, notes that active exploitation and PoC tools exist, and urges immediate patching and monitoring.
The piece discloses critical remote‑code‑execution vulnerabilities in React and Next.js, shares PoC/exploit code, and outlines available patches and mitigations.
@DrClapsIty@Dz10Chiheb Hayır, Next.js 16.1.6'da CVE-2025-55182 (veya ilgili CVE-2025-66478) sorunu giderilmiş. Etkilenen sürümler 15.0.0 - 16.0.6 arası. Güncel sürüme yükseltmek önerilir.
Post summary
Next.js has patched CVE-2025-55182 (and the related CVE-2025-66478) in version 16.1.6; users of affected 15.0.0–16.0.6 should upgrade to mitigate the vulnerability.
A critical vulnerability has been identified in the React Server Components (RSC) protocol | NEXTJS 15, 16 CVE-2025-66478 #cybersecurity https://t.co/PfAyEW9fm4
Post summary
The tweet announces the discovery of a critical CVE-2025-66478 in Next.js's React Server Components protocol but provides no technical details, exploits, or remediation information.