• News/
  • https://www.bleepingcomputer.com/news/security/critical-react2shell-flaw-exploited-in-ransomware-attacks/

Critical React2Shell flaw exploited in ransomware attacks

BleepingComputer
·
Bill Toulas
·
Published Dec 17, 2025
·
Updated

A ransomware gang exploited the critical React2Shell vulnerability (CVE-2025-55182) to gain initial access to corporate networks and deployed the file-encrypting malware less than a minute later. React2Shell is an insecure deserialization issue in the React Server Components (RSC) 'Flight' protocol used by the React library and the Next.js framework. It can be exploited remotely without authentication to execute  JavaScript code in the server's context. Within hours of its disclosure, nation-state hackers started to exploit it in cyberespionage operations or to deploy new EtherRAT malware. Cybercriminals were also quick to leverage it in cryptocurrency mining attacks. However, researchers at corporate intelligence and cybersecurity company S-RM observed React2Shell being used in an attack on December 5 by a threat actor that deployed the Weaxor ransomware strain. Weaxor ransomware appeared in late 2024 and is believed to be a rebrand of the Mallox/FARGO operation (also known as 'TargetCompany') that focused on compromising MS-SQL servers. Like Mallox, Weaxor is a less sophisticated operation that targets public-facing servers with opportunistic attacks demanding relatively low ransoms. The operation does not have a data leak portal for double extortion, and there’s no indication that it performs data exfiltration before the encryption phase. S-RM researchers say that the threat actor deployed the encryptor shortly after gaining initial access through React2Shell. While this ...

Read full article

Affected Software

2 affected components
Meta React
Vercel Next.js
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of the critical React2Shell vulnerability in ransomware attacks.

2

What security implications are discussed?

The article highlights how the React2Shell vulnerability allows attackers to gain initial access to corporate networks for deploying ransomware.

3

What specific vulnerability is mentioned in the article?

The article mentions the vulnerability identified as CVE-2025-55182, known as React2Shell.

4

Which products or software are affected by the React2Shell vulnerability?

The affected software includes Meta React and Vercel Next.js frameworks.

5

How quickly can attackers deploy malware after exploiting this vulnerability?

Attackers can deploy file-encrypting malware in less than a minute after exploiting the React2Shell vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203