Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Reaction Commerce (acquired by Mailchimp)

Reaction Commerce (acquired by Mailchimp) Vendor Cyber Rating & Cyber Score

reactioncommerce.com

We’re building the ecommerce platform we’ve always dreamed of—the next and last platform you’ll ever need. Reaction Commerce is the first real-time, open commerce solution built for the scale and growth of ambitious retailers and brands, and combines the freedom and control designers and developers seek. Our mission is to continuously rethink the commerce experience.


RC A.I CyberSecurity Scoring

RC
Company Information
Website:https://reactioncommerce.com
Employees number:1
Number of followers:661
NAICS:5112
Industry Type:Software Development
Homepage:reactioncommerce.com
RC Risk Score (AI oriented)
Between 700 and 749
logo
RCSoftware Development
Updated:
10/03/2026
735/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
RC Global Score (TPRM)
xxxx
logo
RCSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

RC
RCModerate
Current Score
735Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
736Before Incident
MAY 2026
736Before Incident
APRIL 2026
735Before Incident
MARCH 2026
735Before Incident
FEBRUARY 2026
734Before Incident
JANUARY 2026
734Before Incident
DECEMBER 2025
733Before Incident
NOVEMBER 2025
733Before Incident
OCTOBER 2025
732Before Incident
SEPTEMBER 2025
732Before Incident
AUGUST 2025
731Before Incident
JULY 2025
731Before Incident
JUNE 2025
749Before Incident
Cyber Attack
16 Jun 2025RC
Unnamed IT Sector Organizations and React Server Components: Attackers Exploiting React2Shell Vulnerability to Attack IT Sectors

React2Shell Exploits Target Insurance, E-Commerce, and IT Sectors

730After Incident
CRITICAL-19
INFREA1769533068
React2Shell Exploits Target Insurance, E-Commerce, and IT Sectors in Rapid Cyberattacks Threat actors are actively exploiting CVE-2025-55182 (React2Shell), a critical vulnerability in React Server Components, to compromise organizations in the insurance, e-commerce, and IT sectors. The flaw stems from insecure deserialization in the Flight protocol, enabling attackers to execute unauthorized code on vulnerable servers. Exploitation campaigns have moved swiftly, with adversaries weaponizing the vulnerability within hours of disclosure. While many critical flaws never see real-world use, React2Shell has become a prime target, delivering XMRig cryptocurrency miners, botnets, and remote access tools. ### Attack Scope and Malware Payloads - Russian entities faced attacks deploying RustoBot and Kaiji botnets, which conduct DDoS attacks and establish persistence via systemd services, crontab tasks, and modified system utilities. - Global campaigns distributed a broader range of malware, including: - CrossC2 implants (Cobalt Strike payloads with AES-128-CBC encryption) - Tactical RMM (remote management tool abuse) - VShell backdoors - EtherRAT (JavaScript-based malware retrieving C2 addresses from Ethereum smart contracts) ### Affected Systems and Patches React2Shell impacts multiple React Server Component packages, including: - react-server-dom-webpack - react-server-dom-parcel - react-server-dom-turbopack (versions 19.0, 19.1.0, 19.1.1, 19.2.0) Patches are available in versions 19.0.1, 19.1.2, and 19.2.1, but security experts warn that patching alone is insufficient. Organizations must also scan for post-exploitation activity, as attackers often deploy multiple malicious tools in a single breach. ### Infection Mechanism 1. Initial Access: Attackers exploit React2Shell to execute commands in compromised containers. 2. Malware Deployment: Bash scripts (e.g., wocaosinm.sh, setup2.sh) download architecture-specific payloads, including: - Kaiji botnet (DDoS attacks, persistence via systemd/crontab) - XMRig miner (version 6.24.0, with CPU throttling to evade detection) 3. Data Exfiltration: Attackers use DNS tunneling (nslookup) to encode and transmit stolen data via subdomain queries. 4. Persistence Techniques: - CrossC2 payloads disguise themselves as "Rsyslo AV Agent Service" via systemd. - EtherRAT employs five persistence methods, including XDG Autostart, .bashrc, and .profile modifications. ### Mitigation Recommendations Beyond patching, organizations should: - Verify Next.js versions and dependencies - Rebuild projects after updates - Check lock files to ensure vulnerable packages are removed - Restrict experimental React Server Components in production unless fully patched The attacks highlight the speed and sophistication of modern cyber threats, with adversaries rapidly adapting to newly disclosed vulnerabilities.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
MOTIVATION
Financial gain (cryptocurrency mining)Botnet deploymentRemote access
IMPACT
Data Compromised: Potential data exfiltration via DNS tunnelingSystems Affected: Servers running vulnerable React Server Components (react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack)Operational Impact: DDoS attacks, unauthorized remote access, system resource consumption (cryptocurrency mining)
DATA BREACH
Data Exfiltration: Possible via DNS tunneling (nslookup)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for RC ?
?
What was RC's A.I Rankiteo Cyber Score in May 2026 ?
?
What was RC's A.I Rankiteo Cyber Score in April 2026 ?
?
What was RC's A.I Rankiteo Cyber Score in March 2026 ?
?
What was RC's A.I Rankiteo Cyber Score in February 2026 ?
?
What was RC's A.I Rankiteo Cyber Score in January 2026 ?
?
What was RC's A.I Rankiteo Cyber Score in December 2025 ?
?
What was RC's A.I Rankiteo Cyber Score in November 2025 ?
?
What was RC's A.I Rankiteo Cyber Score in October 2025 ?
?
What was RC's A.I Rankiteo Cyber Score in September 2025 ?
?
What was RC's A.I Rankiteo Cyber Score in August 2025 ?
?
What was RC's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on RC's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with RC ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view RC's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?