• News/
  • https://www.bleepingcomputer.com/news/security/google-links-more-chinese-hacking-groups-to-react2shell-attacks/

Google links more Chinese hacking groups to React2Shell attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Dec 15, 2025
·
Updated

​Over the weekend, ​Google's threat intelligence team linked five more Chinese hacking groups to attacks exploiting the maximum-severity "React2Shell" remote code execution vulnerability. Tracked as CVE-2025-55182, this actively exploited flaw affects the React open-source JavaScript library and allows unauthenticated attackers to execute arbitrary code in React and Next.js applications with a single HTTP request. While multiple React packages (i.e., react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack) are vulnerable in their default configurations, the vulnerability only affects React versions 19.0, 19.1.0, 19.1.1, and 19.2.0 released over the past year. After the attacks began, Palo Alto Networks reported that dozens of organizations had been breached, including incidents linked to Chinese state-backed threat actors. The attackers are exploiting the flaw to execute commands and steal AWS configuration files, credentials, and other sensitive information. The Amazon Web Services (AWS) security team also warned that the China-linked Earth Lamia and Jackpot Panda threat actors had begun exploiting React2Shell within hours of the vulnerability's disclosure. On Saturday, the Google Threat Intelligence Group (GTIG) reported detecting at least five more Chinese cyber-espionage groups joining ongoing React2Shell attacks that started after the flaw was disclosed on December 3. The list of state-linked threat groups exploiting the flaw now also includes ...

Read full article

Affected Software

4 affected components
Facebook React=19.0
Facebook React=19.1.0
Facebook React=19.1.1
Facebook React=19.2.0
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Google's identification of five Chinese hacking groups linked to the React2Shell attacks exploiting a remote code execution vulnerability.

2

What security implications are discussed regarding React2Shell?

The article highlights the severity of the CVE-2025-55182 vulnerability, which poses a significant risk as it allows remote code execution.

3

Which software products are affected by the React2Shell vulnerability?

The affected software products are various versions of Facebook React, specifically versions 19.0, 19.1.0, 19.1.1, and 19.2.0.

4

What new information did Google provide about the hacking groups?

Google's threat intelligence team linked several additional Chinese hacking groups to the attacks that exploit the React2Shell vulnerability.

5

Why is the React2Shell vulnerability considered maximum severity?

It is classified as maximum severity due to its potential to allow attackers to execute arbitrary code on affected systems, increasing the risk of data breaches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203