Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
React2Shell_Hunter — AWS Organization-wide detection toolkit for CVE-2025-55182 & CVE-2025-66478 (React Server Components / Next.js RCE vulnerabilities) | Kitploit
Tools/GitHubGitHub/rocklambros/react2shell_hunter
Defensive ToolsVulnerability ScannersExploitationWeb SecurityCloud SecurityThreat IntelligenceIntrusion DetectionIncident ResponseLog Analysis
GitHubrocklambros/react2shell_hunter

React2Shell_Hunter

AWS Organization-wide detection toolkit for CVE-2025-55182 & CVE-2025-66478 (React Server Components / Next.js RCE vulnerabilities)

1279 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
Share

React2Shell Hunter

AWS Organization-Wide Detection Toolkit for CVE-2025-55182 & CVE-2025-66478


⚠️ IMPORTANT DISCLAIMER - PLEASE READ BEFORE USE

This toolkit has NOT been tested in a production AWS environment.

Due to infrastructure constraints, this project was developed and validated through code review, static analysis, and documentation verification only. It has not been deployed to or tested against a live AWS environment with active GuardDuty, WAF, EventBridge, or CloudTrail services.

What This Means For You:

ComponentStatus
Python Scanner Logic✅ Code reviewed, Snyk validated
Terraform Syntax✅ Validated, not applied
IAM Policies⚠️ May require adjustment for your environment
EventBridge Rules⚠️ Finding patterns based on AWS documentation
WAF Rules⚠️ Regex patterns untested against live traffic
Athena Queries⚠️ Schema assumptions may need modification

Recommendations:

  1. Deploy to a non-production account first - Test all components in a sandbox environment
  2. Review IAM policies carefully - Adjust permissions to match your organization's requirements
  3. Validate Terraform plans - Run terraform plan and review before applying
  4. Test EventBridge patterns - Verify finding type strings match your GuardDuty output
  5. Monitor CloudWatch logs - Check for errors after deployment

Liability:

This software is provided "AS IS" without warranty of any kind. The authors assume no responsibility for any damage, security incidents, or AWS costs incurred through the use of this toolkit. Use at your own risk.

If you successfully deploy and test this toolkit, please consider contributing your findings back to improve it for the community.


A comprehensive security toolkit for detecting React2Shell exploitation attempts across AWS environments. This toolkit provides real-time detection, threat hunting capabilities, and automated response for the critical React Server Components RCE vulnerability.


Table of Contents

  1. What This Toolkit Detects
  2. Prerequisites
  3. Installation
  4. Quick Start
  5. Architecture Deep Dive
  6. Component Reference
  7. Deployment Guide
  8. IOC Reference
  9. Troubleshooting
  10. FAQ

What This Toolkit Detects

CVE-2025-55182 (React Server Components)

  • CVSS Score: 10.0 (Maximum severity)
  • Attack Vector: Network, no authentication required
  • Root Cause: Prototype pollution via unsafe deserialization in React's "Flight" protocol
  • Exploitation: __proto__:then manipulation enables arbitrary code execution via process.mainModule.require('child_process').execSync()

CVE-2025-66478 (Next.js)

  • Downstream Impact: Next.js frameworks using vulnerable React versions
  • Affected Versions: Next.js 15.0.4, 15.1.8, 15.2.5, 15.3.5, 15.4.7, 15.5.6, 16.0.6, and 14.3.0-canary.77+

Attack Chain This Toolkit Detects

1. INITIAL ACCESS     → WAF detects Next-Action header + prototype pollution payloads
2. EXECUTION          → GuardDuty ThreatIntelSet detects C2 IP connections
3. CREDENTIAL THEFT   → CloudTrail detects GetCallerIdentity from EC2 roles
4. LATERAL MOVEMENT   → EventBridge rules detect SSM SendCommand/StartSession
5. EXFILTRATION       → DNS exfiltration to ceye.io/dnslog.cn detected
6. CRYPTOMINING       → GuardDuty detects cryptocurrency mining activity

Prerequisites

Required Permissions

# Minimum IAM permissions for the detection script
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "cloudtrail:LookupEvents",
        "logs:StartQuery",
        "logs:GetQueryResults",
        "guardduty:ListDetectors",
        "guardduty:ListFindings",
        "guardduty:GetFindings",
        "guardduty:CreateThreatIntelSet",
        "guardduty:UpdateThreatIntelSet",
        "guardduty:ListThreatIntelSets",
        "guardduty:GetThreatIntelSet",
        "s3:PutObject",
        "s3:GetObject",
        "sts:GetCallerIdentity",
        "sts:AssumeRole"
      ],
      "Resource": "*"
    }
  ]
}

# For Security Hub integration, add:
"securityhub:BatchImportFindings"

# For SNS alerting, add:
"sns:Publish"

# For organization-wide scanning, add:
"organizations:ListAccounts"

Software Requirements

SoftwareVersionPurpose
Python3.9+Detection script runtime
Terraform1.0+Infrastructure deployment
AWS CLI2.xAWS authentication
boto31.34+AWS SDK for Python

Installation

Step 1: Clone and Install Dependencies

# Navigate to project
cd React2Shell_Hunter

# Create virtual environment (RECOMMENDED)
python3 -m venv venv
source venv/bin/activate  # On Windows: venv\Scripts\activate

# Install dependencies
pip install -r requirements.txt

Step 2: Configure AWS Credentials

# Option A: Use AWS CLI profile
aws configure --profile security-scanner

# Option B: Export environment variables
export AWS_ACCESS_KEY_ID="your-access-key"
export AWS_SECRET_ACCESS_KEY="your-secret-key"
export AWS_DEFAULT_REGION="us-east-1"

# Option C: Use IAM role (recommended for EC2/Lambda)
# Attach appropriate IAM role to your compute resource

Step 3: Verify Installation

# Test AWS connectivity
aws sts get-caller-identity

# Test Python dependencies
python -c "import boto3, yaml; print('Dependencies OK')"

# Test IOC loading
python -c "
import yaml
with open('config/iocs.yaml') as f:
    iocs = yaml.safe_load(f)
    print(f'Loaded {len(iocs[\"network_iocs\"][\"malicious_ips\"])} malicious IPs')
"

Quick Start

Scan Current Account (Last 24 Hours)

python src/react2shell_detector.py --hours 24

Expected Output:

2025-12-06 10:00:00 - React2ShellDetector - INFO - ============================================================
2025-12-06 10:00:00 - React2ShellDetector - INFO - React2Shell IOC Detection Script
2025-12-06 10:00:00 - React2ShellDetector - INFO - CVE-2025-55182 & CVE-2025-66478
2025-12-06 10:00:00 - React2ShellDetector - INFO - ============================================================
2025-12-06 10:00:00 - React2ShellDetector - INFO - Starting single account scan...
2025-12-06 10:00:00 - React2ShellDetector - INFO - Analyzing CloudTrail logs...
2025-12-06 10:00:05 - React2ShellDetector - INFO - Checking GuardDuty findings...

Total findings: 0
  CRITICAL: 0
  HIGH: 0
  MEDIUM: 0

Full Production Scan

python src/react2shell_detector.py \
    --organization \
    --role-name SecurityAuditRole \
    --security-hub \
    --guardduty-bucket my-threat-intel-bucket-12345 \
    --vpc-log-group /aws/vpc/flowlogs \
    --waf-log-group aws-waf-logs-react2shell \
    --sns-topic arn:aws:sns:us-east-1:123456789012:security-alerts \
    --output json \
    --output-file findings-$(date +%Y%m%d).json \
    --hours 72

Architecture Deep Dive

Critical Concept: How GuardDuty Detection Works

YOU CANNOT CREATE CUSTOM DETECTION RULES IN GUARDDUTY.

GuardDuty uses ML models and threat intelligence to generate findings. To detect React2Shell:

  1. ThreatIntelSet: Upload C2 IPs to GuardDuty → Generates MaliciousIPCaller.Custom findings
  2. EventBridge: Filter specific finding types → Route to SNS/Lambda/CloudWatch
  3. Response: Receive alerts, trigger automation, investigate
Download Tool