
AWS Organization-wide detection toolkit for CVE-2025-55182 & CVE-2025-66478 (React Server Components / Next.js RCE vulnerabilities)
AWS Organization-Wide Detection Toolkit for CVE-2025-55182 & CVE-2025-66478
⚠️ IMPORTANT DISCLAIMER - PLEASE READ BEFORE USE
This toolkit has NOT been tested in a production AWS environment.
Due to infrastructure constraints, this project was developed and validated through code review, static analysis, and documentation verification only. It has not been deployed to or tested against a live AWS environment with active GuardDuty, WAF, EventBridge, or CloudTrail services.
What This Means For You:
Component Status Python Scanner Logic ✅ Code reviewed, Snyk validated Terraform Syntax ✅ Validated, not applied IAM Policies ⚠️ May require adjustment for your environment EventBridge Rules ⚠️ Finding patterns based on AWS documentation WAF Rules ⚠️ Regex patterns untested against live traffic Athena Queries ⚠️ Schema assumptions may need modification Recommendations:
- Deploy to a non-production account first - Test all components in a sandbox environment
- Review IAM policies carefully - Adjust permissions to match your organization's requirements
- Validate Terraform plans - Run
terraform planand review before applying- Test EventBridge patterns - Verify finding type strings match your GuardDuty output
- Monitor CloudWatch logs - Check for errors after deployment
Liability:
This software is provided "AS IS" without warranty of any kind. The authors assume no responsibility for any damage, security incidents, or AWS costs incurred through the use of this toolkit. Use at your own risk.
If you successfully deploy and test this toolkit, please consider contributing your findings back to improve it for the community.
A comprehensive security toolkit for detecting React2Shell exploitation attempts across AWS environments. This toolkit provides real-time detection, threat hunting capabilities, and automated response for the critical React Server Components RCE vulnerability.
__proto__:then manipulation enables arbitrary code execution via process.mainModule.require('child_process').execSync()1. INITIAL ACCESS → WAF detects Next-Action header + prototype pollution payloads
2. EXECUTION → GuardDuty ThreatIntelSet detects C2 IP connections
3. CREDENTIAL THEFT → CloudTrail detects GetCallerIdentity from EC2 roles
4. LATERAL MOVEMENT → EventBridge rules detect SSM SendCommand/StartSession
5. EXFILTRATION → DNS exfiltration to ceye.io/dnslog.cn detected
6. CRYPTOMINING → GuardDuty detects cryptocurrency mining activity
# Minimum IAM permissions for the detection script
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"cloudtrail:LookupEvents",
"logs:StartQuery",
"logs:GetQueryResults",
"guardduty:ListDetectors",
"guardduty:ListFindings",
"guardduty:GetFindings",
"guardduty:CreateThreatIntelSet",
"guardduty:UpdateThreatIntelSet",
"guardduty:ListThreatIntelSets",
"guardduty:GetThreatIntelSet",
"s3:PutObject",
"s3:GetObject",
"sts:GetCallerIdentity",
"sts:AssumeRole"
],
"Resource": "*"
}
]
}
# For Security Hub integration, add:
"securityhub:BatchImportFindings"
# For SNS alerting, add:
"sns:Publish"
# For organization-wide scanning, add:
"organizations:ListAccounts"
| Software | Version | Purpose |
|---|---|---|
| Python | 3.9+ | Detection script runtime |
| Terraform | 1.0+ | Infrastructure deployment |
| AWS CLI | 2.x | AWS authentication |
| boto3 | 1.34+ | AWS SDK for Python |
# Navigate to project
cd React2Shell_Hunter
# Create virtual environment (RECOMMENDED)
python3 -m venv venv
source venv/bin/activate # On Windows: venv\Scripts\activate
# Install dependencies
pip install -r requirements.txt
# Option A: Use AWS CLI profile
aws configure --profile security-scanner
# Option B: Export environment variables
export AWS_ACCESS_KEY_ID="your-access-key"
export AWS_SECRET_ACCESS_KEY="your-secret-key"
export AWS_DEFAULT_REGION="us-east-1"
# Option C: Use IAM role (recommended for EC2/Lambda)
# Attach appropriate IAM role to your compute resource
# Test AWS connectivity
aws sts get-caller-identity
# Test Python dependencies
python -c "import boto3, yaml; print('Dependencies OK')"
# Test IOC loading
python -c "
import yaml
with open('config/iocs.yaml') as f:
iocs = yaml.safe_load(f)
print(f'Loaded {len(iocs[\"network_iocs\"][\"malicious_ips\"])} malicious IPs')
"
python src/react2shell_detector.py --hours 24
Expected Output:
2025-12-06 10:00:00 - React2ShellDetector - INFO - ============================================================
2025-12-06 10:00:00 - React2ShellDetector - INFO - React2Shell IOC Detection Script
2025-12-06 10:00:00 - React2ShellDetector - INFO - CVE-2025-55182 & CVE-2025-66478
2025-12-06 10:00:00 - React2ShellDetector - INFO - ============================================================
2025-12-06 10:00:00 - React2ShellDetector - INFO - Starting single account scan...
2025-12-06 10:00:00 - React2ShellDetector - INFO - Analyzing CloudTrail logs...
2025-12-06 10:00:05 - React2ShellDetector - INFO - Checking GuardDuty findings...
Total findings: 0
CRITICAL: 0
HIGH: 0
MEDIUM: 0
python src/react2shell_detector.py \
--organization \
--role-name SecurityAuditRole \
--security-hub \
--guardduty-bucket my-threat-intel-bucket-12345 \
--vpc-log-group /aws/vpc/flowlogs \
--waf-log-group aws-waf-logs-react2shell \
--sns-topic arn:aws:sns:us-east-1:123456789012:security-alerts \
--output json \
--output-file findings-$(date +%Y%m%d).json \
--hours 72
YOU CANNOT CREATE CUSTOM DETECTION RULES IN GUARDDUTY.
GuardDuty uses ML models and threat intelligence to generate findings. To detect React2Shell:
MaliciousIPCaller.Custom findings