Over the weekend, Google's threat intelligence team linked five more Chinese hacking groups to attacks exploiting the maximum-severity "React2Shell" remote code execution vulnerability. Tracked as CVE-2025-55182, this actively exploited flaw affects the React open-source JavaScript library and allows unauthenticated attackers to execute arbitrary code in React and Next.js applications with a single HTTP request. While multiple React packages (i.e., react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack) are vulnerable in their default configurations, the vulnerability only affects React versions 19.0, 19.1.0, 19.1.1, and 19.2.0 released over the past year. After the attacks began, Palo Alto Networks reported that dozens of organizations had been breached, including incidents linked to Chinese state-backed threat actors. The attackers are exploiting the flaw to execute commands and steal AWS configuration files, credentials, and other sensitive information. The Amazon Web Services (AWS) security team also warned that the China-linked Earth Lamia and Jackpot Panda threat actors had begun exploiting React2Shell within hours of the vulnerability's disclosure. On Saturday, the Google Threat Intelligence Group (GTIG) reported detecting at least five more Chinese cyber-espionage groups joining ongoing React2Shell attacks that started after the flaw was disclosed on December 3. The list of state-linked threat groups exploiting the flaw now also includes ...
Google links more Chinese hacking groups to React2Shell attacks
BleepingComputer
·Sergiu Gatlan
·Published Dec 15, 2025
·Updated
Affected Software
4 affected components
Facebook React=19.0
Facebook React=19.1.0
Facebook React=19.1.1
Facebook React=19.2.0
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Google's identification of five Chinese hacking groups linked to the React2Shell attacks exploiting a remote code execution vulnerability.
2
What security implications are discussed regarding React2Shell?
The article highlights the severity of the CVE-2025-55182 vulnerability, which poses a significant risk as it allows remote code execution.
3
Which software products are affected by the React2Shell vulnerability?
The affected software products are various versions of Facebook React, specifically versions 19.0, 19.1.0, 19.1.1, and 19.2.0.
4
What new information did Google provide about the hacking groups?
Google's threat intelligence team linked several additional Chinese hacking groups to the attacks that exploit the React2Shell vulnerability.
5
Why is the React2Shell vulnerability considered maximum severity?
It is classified as maximum severity due to its potential to allow attackers to execute arbitrary code on affected systems, increasing the risk of data breaches.