AI/LLM-Generated Malware Used to Exploit React2Shell
An AI-generated malware sample exploited CVE-2025-55182, known as React2Shell, within a Docker honeypot with an exposed daemon. This resulted in remote code execution, allowing the deployment of an XMRig cryptominer on over ninety compromised hosts and demonstrating the operational value of LLMs for low-skill adversaries.
STABLE
What Happened
An AI-generated malware sample exploited CVE-2025-55182, known as React2Shell, within a Docker honeypot with an exposed daemon. This resulted in remote code execution, allowing the deployment of an XMRig cryptominer on over ninety compromised hosts and demonstrating the operational value of LLMs for low-skill adversaries.
Why This Matters
Publisher reporting describes a security event affecting for. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether for is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
Exposure
Exposure unknown
May 18, 2026 12:30
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Authoritative Intelligence
Public GitHub References
Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ it does not fetch or display exploit code.
CVE-2025-55182: 6 public repository references found.
Possible public PoC reference
Explanation and full RCE PoC for CVE-2025-55182
1429 stars ยท Python
Open repositoryPossible public PoC reference
Original Proof-of-Concepts for React2Shell CVE-2025-55182
1062 stars ยท JavaScript
Open repositoryPossible public PoC reference
CVE-2025-55182 POC
792 stars ยท JavaScript
Open repositoryPossible public PoC reference
RSC/Next.js RCE Vulnerability Detector & PoC Chrome Extension โ CVE-2025-55182 & CVE-2025-66478
314 stars ยท JavaScript
Open repositoryPossible public PoC reference
React2Shell Proof of Concept
92 stars ยท Python
Open repositoryPossible public PoC reference
Docker poc lab for CVE-2025-55182 / CVE-2025-66478 (React2Shell) detection and exploitation
88 stars ยท JavaScript
Open repositoryA public PoC or exploit-related repository means weaponization material may exist in the open. It does not prove your environment was targeted.
Timeline
-
Incident first seen
Feb 10, 2026 05:30BugSkan first recorded this incident.
-
AI/LLM-Generated Malware Used to Exploit React2Shell - Darktrace
Feb 10, 2026 05:30darktrace.com ยท Malware
-
AI shrinks vulnerability exploitation window to hours - Help Net Security
May 18, 2026 12:30news.google.com ยท Vulnerability
-
Latest observed development
May 18, 2026 12:30Most recent source or update associated with this incident.
Sources
darktrace.com ยท Feb 10, 2026 05:30
An AI-generated malware sample exploited CVE-2025-55182, known as React2Shell, within a Docker honeypot with an exposed daemon. This resulted in remote code execution, allowing the deployment of an XMRig cryptominer on over ninety compromised hosts and demonstrating the operational value of LLMs for low-skill adversaries.
Open publisher sourcenews.google.com ยท May 18, 2026 12:30
AI shrinks vulnerability exploitation window to hours Help Net Security
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.