AI/LLM-Generated Malware Used to Exploit React2Shell
An AI-generated malware sample exploited CVE-2025-55182, known as React2Shell, within a Docker honeypot with an exposed daemon. This resulted in remote code execution, allowing the deployment of an XMRig cryptominer on over ninety compromised hosts and demonstrating the operational value of LLMs for low-skill adversaries.
STABLE
What Happened
An AI-generated malware sample exploited CVE-2025-55182, known as React2Shell, within a Docker honeypot with an exposed daemon. This resulted in remote code execution, allowing the deployment of an XMRig cryptominer on over ninety compromised hosts and demonstrating the operational value of LLMs for low-skill adversaries.
Why This Matters
Publisher reporting describes a security event affecting for. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether for is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
Exposure
Exposure unknown
May 18, 2026 12:30
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Authoritative Intelligence
Public GitHub References
Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ it does not fetch or display exploit code.
Timeline
-
Incident first seen
Feb 10, 2026 05:30BugSkan first recorded this incident.
-
AI/LLM-Generated Malware Used to Exploit React2Shell - Darktrace
Feb 10, 2026 05:30darktrace.com ยท Malware
-
AI shrinks vulnerability exploitation window to hours - Help Net Security
May 18, 2026 12:30news.google.com ยท Vulnerability
-
Latest observed development
May 18, 2026 12:30Most recent source or update associated with this incident.
Sources
darktrace.com ยท Feb 10, 2026 05:30
An AI-generated malware sample exploited CVE-2025-55182, known as React2Shell, within a Docker honeypot with an exposed daemon. This resulted in remote code execution, allowing the deployment of an XMRig cryptominer on over ninety compromised hosts and demonstrating the operational value of LLMs for low-skill adversaries.
Open publisher sourcenews.google.com ยท May 18, 2026 12:30
AI shrinks vulnerability exploitation window to hours Help Net Security
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.