North Korean Hackers Exploit React2Shell Vulnerability to Target Cryptocurrency
Cybersecurity firm Sysdig has identified that North Korean threat actors are exploiting a vulnerability known as React2Shell, officially tracked as CVE-2025-55182, which affects version 19 of the React open source library. This vulnerability allows for unauthenticated remote code execution and has been used in attacks targeting cryptocurrency and blockchain technologies. The attacks involve the deployment of EtherRAT, a persistent access implant that combines techniques from multiple documented campaigns. The goal of these attacks is to steal cryptocurrency from victims. The React2Shell vulnerability impacts not only React but also related frameworks such as Next.js, Waku, React Router, and RedwoodSDK. Despite React powering millions of applications, the number of vulnerable instances is relatively small, with approximately 70,000 affected systems identified by the Shadowserver Foundation.