React2Shell Chaos: Chinese Hackers Exploit Critical React Vulnerability for Cyber Mischief

Chinese threat groups are exploiting React2Shell like it’s a Black Friday sale on vulnerabilities. This newly disclosed bug, CVE-2025-55182, is the latest hot-ticket item, allowing hackers to execute remote code on systems using React 19. Google’s watching as malware flies off the shelves, courtesy of Earth Lamia and Jackpot Panda.

Pro Dashboard

Hot Take:

React2Shell sounds like a hip new dance move, but the only ones grooving are cybercriminals exploiting this vulnerability. Our new dance partners include five China-linked threat groups who have taken to the digital dance floor faster than you can say “unauthenticated remote code execution.” It’s like a cybersecurity version of Dancing with the Stars, except the stars are malicious and the judges are probably crying.

Key Points:

  • Google observed five China-linked threat groups exploiting the React2Shell vulnerability.
  • React2Shell impacts systems using React version 19 and can lead to remote code execution.
  • Threat actors include groups with catchy names like Earth Lamia, Jackpot Panda, and UNC6600.
  • Additional React vulnerabilities have been disclosed, with varying severity levels.
  • Attacks are not limited to Chinese groups; Iran-linked threat actors are also getting in on the action.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?