React A.I CyberSecurity Scoring
React
Company Information
Website:http://react.nl
Employees number:38
Number of followers:3,902
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:react.nl
React Risk Score (AI oriented)
Between 700 and 749
ReactTechnology, Information and Internet
Updated:
04/04/2026
04/04/2026
746/1000
Moderate
Ba
React Global Score (TPRM)
xxxx
ReactTechnology, Information and Internet
Score locked

ReactModerate
Current Score
746Ba (MODERATE)
01000
2 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
748
JULY 2026
747
JUNE 2026
747
MAY 2026
747
APRIL 2026
747
MARCH 2026
746
FEBRUARY 2026
746
JANUARY 2026
746
DECEMBER 2025
750
Vulnerability
01 Dec 2025 • React
React and Next.js: React2Shell Vulnerability Exploited in the Wild, Analysts Warn
Critical React2Shell Exploit (CVE-2025-55182) Drives Large-Scale Attack Campaign
745
CRITICAL-5
NEXREA1770731681
Critical React2Shell Exploit (CVE-2025-55182) Drives Large-Scale Attack Campaign
A newly disclosed critical vulnerability, React2Shell (CVE-2025-55182), enables pre-authentication remote code execution (RCE) in React Server Components, affecting multiple versions within the React 19 ecosystem. The flaw stems from improper parsing of server-side component payloads, allowing attackers to exploit it via crafted network requests.
The WXA Internet Abuse Signal Collective (WXA IASC) has launched To Cache A Predator, a threat research series tracking attacker infrastructure and tactics tied to the exploit. Initial findings reveal rapid weaponization following the vulnerability’s public disclosure in early December 2025, with persistent scanning targeting Next.js paths, particularly `/_next/server` and `/_next/static/*`.
Early Exploitation & Attack Infrastructure
WXA IASC’s Niihama honeypots detected exploitation attempts within 20 hours of disclosure, capturing exploit mechanics and attacker behavior. Scanning activity persisted through early February 2026, with two Netherlands-hosted IPs 193.142.147[.]209 and 87.121.84[.]24 accounting for 56% of observed React2Shell traffic between January 26 and February 2, 2026. GreyNoise data corroborated this, recording 1.4 million exploitation attempts during that period, with the two IPs responsible for 799,826 sessions (56%).
The ILOVEPOOP Toolkit
WXA IASC attributes much of the high-fidelity exploitation to a novel toolkit dubbed "ILOVEPOOP", operated by a single threat actor across nine scanner nodes. The toolkit is identifiable by distinct headers:
- `Next-Action: x`
- `X-Nextjs-Request-Id: poop1234`
- `X-Nextjs-Html-Request-Id: ilovepoop_*`
- A repeatable six-path Next.js sweep and a shared User-Agent rotation.
Niihama also observed follow-on attacks (SMB, RDP, SSH, HTTP, and credential abuse) from IPs linked to the same infrastructure, suggesting reconnaissance rather than confirmed breaches.
Defensive Measures
Organizations are advised to patch affected React/Next.js deployments and monitor logs for suspicious patterns, including Server Actions–like POST requests and the ILOVEPOOP canary headers. Defenders should prioritize exposure reduction and least-privilege access for internet-facing systems.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
NOVEMBER 2025
750
OCTOBER 2025
750
SEPTEMBER 2025
750
JANUARY 2025
765
Vulnerability
01 Jan 2025 • React
React Server Components / Next.js: DPRK Hackers Target Crypto Firms, Steal Keys and Cloud Assets in Coordinated Attacks
DPRK-Linked Threat Actors Exploit React2Shell Flaw in Large-Scale Crypto Heists
748
CRITICAL-17
REA1772713454
DPRK-Linked Threat Actors Exploit React2Shell Flaw in Large-Scale Crypto Heists
Suspected North Korea-linked threat actors have launched a sophisticated campaign targeting cryptocurrency firms, leveraging a critical vulnerability in React Server Components and Next.js to steal digital assets and sensitive infrastructure data. The attacks, which span web-app exploitation, cloud abuse, and secrets theft, follow a full kill chain from initial access to deep reconnaissance and exfiltration.
The campaign exploits CVE-2025-55182 (React2Shell), an unauthenticated remote code execution flaw with a CVSS score of 10.0, allowing attackers to execute arbitrary commands on vulnerable servers. Threat actors used mass-scanning tools and WAF-bypass techniques to identify exposed crypto staking platforms, particularly those handling USDT staking. In one case, investigators recovered compromised backend source code containing Tron wallet addresses, private keys, and a Python script reusing those keys for balance checks. Blockchain records suggest at least one suspicious TRX transfer coincided with active exploitation, though direct attribution remains unconfirmed.
Beyond web exploitation, the same threat group abused AWS access tokens to infiltrate a separate crypto exchange. After validating credentials via AWS Security Token Service (STS), they systematically enumerated core cloud services S3, RDS, EC2, Lambda, EKS, and IAM searching for high-value artifacts like kubeconfig files, Terraform state files, and hardcoded credentials. Terraform files were filtered for terms such as "password," "db_name," and "public_ip," providing a detailed blueprint of the victim’s infrastructure.
The attackers then pivoted to Kubernetes, using `aws eks update-kubeconfig` to gain access to managed EKS clusters. They listed pods across namespaces, pulled sensitive Docker images from private ECR registries, and exfiltrated at least five proprietary exchange images containing hardcoded credentials and internal routing details. Additional secrets were extracted from AWS Secrets Manager, Kubernetes ConfigMaps, and running containers, while private Git repositories were cloned for full backend visibility.
Command-and-control (C2) infrastructure relied on a licensed VShell server (port 8082) and Fast Reverse Proxy (FRP) on port 53, a tactic consistent with DPRK-linked operations known for covert tunneling. Core attack servers were hosted on a South Korean VPS (64.176.226[.]36, 2401:c080:1c01:c6:5400:5ff:fec1:ccc9) under the domain itemnania[.]com, with SSH activity and VPN exit nodes used to obscure origins.
Victimology suggests a crypto supply-chain focus, targeting staking platforms, exchange software vendors, and exchanges themselves. Rather than immediate mass theft, the campaign prioritized backend source code, database credentials, private keys, and exchange middleware likely positioning for future large-scale asset theft. While DPRK attribution is assessed with moderate confidence, researchers note that tools like VShell are also used by other nation-state actors. The campaign aligns with North Korea’s documented history of React2Shell exploitation, AWS token abuse in crypto heists, and FRP infrastructure reuse.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for React ??
What was React's A.I Rankiteo Cyber Score in July 2026 ??
What was React's A.I Rankiteo Cyber Score in June 2026 ??
What was React's A.I Rankiteo Cyber Score in May 2026 ??
What was React's A.I Rankiteo Cyber Score in April 2026 ??
What was React's A.I Rankiteo Cyber Score in March 2026 ??
What was React's A.I Rankiteo Cyber Score in February 2026 ??
What was React's A.I Rankiteo Cyber Score in January 2026 ??
What was React's A.I Rankiteo Cyber Score in December 2025 ??
What was React's A.I Rankiteo Cyber Score in November 2025 ??
What was React's A.I Rankiteo Cyber Score in October 2025 ??
What was React's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on React's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with React ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view React's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?