• News/
  • https://www.theregister.com/2025/12/15/react2shell_flaw_china_iran/

React2Shell vuln exploited by China, Iran, Google warns

The Register
·
Jessica Lyons
·
Published Dec 15, 2025
·
Updated

At least five more Chinese spy crews, Iran-linked goons, and financially motivated criminals are now attacking React2Shell, a maximum-severity flaw in the widely used React JavaScript library, according to Google. Unauthenticated attackers can abuse the flaw, tracked as CVE-2025-55182, to remotely execute code, and the Chocolate Factory's threat hunters said multiple groups are using this vulnerability to deploy backdoors, tunnelers, and cryptocurrency miners. React maintainers disclosed the critical bug on December 3, and exploitation began almost immediately. According to Amazon's threat intel team, Chinese government crews, including Earth Lamia and Jackpot Panda, started battering the security hole within hours of its disclosure. Palo Alto Networks' Unit 42 responders have put the victim count at more than 50 organizations across multiple sectors, with attackers from North Korea also abusing the flaw. Google, in a late Friday report, said at least five other suspected PRC spy groups also exploited React2Shell, along with criminals who deployed XMRig for illicit cryptocurrency mining, and "Iran-nexus actors," although the report doesn't provide any additional details about who the Iran-linked groups are and what they are doing after exploitation. "GTIG has also observed numerous discussions regarding CVE-2025-55182 in underground forums, including threads in which threat actors have shared links to scanning tools, proof-of-concept (PoC) code, and their experiences using th...

Read full article

Affected Software

1 affected component
Facebook React
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of the React2Shell vulnerability in the React JavaScript library by state-sponsored attackers from China and Iran, as well as financially motivated criminals.

2

What security implications are discussed?

The article highlights that the React2Shell flaw allows unauthenticated remote code execution, posing significant risks to users of the library.

3

What products or software are affected?

The primary software affected by the vulnerability is the Facebook React JavaScript library.

4

What is the CVE identifier associated with the React2Shell vulnerability?

The vulnerability is tracked under the identifier CVE-2025-55182.

5

Who is warning about the exploitation of the React2Shell flaw?

Google is the organization warning about the exploitation of the React2Shell vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203