Last seen May 18, 2026

AI/LLM-Generated Malware Used to Exploit React2Shell

An AI-generated malware sample exploited CVE-2025-55182, known as React2Shell, within a Docker honeypot with an exposed daemon. This resulted in remote code execution, allowing the deployment of an XMRig cryptominer on over ninety compromised hosts and demonstrating the operational value of LLMs for low-skill adversaries.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

An AI-generated malware sample exploited CVE-2025-55182, known as React2Shell, within a Docker honeypot with an exposed daemon. This resulted in remote code execution, allowing the deployment of an XMRig cryptominer on over ninety compromised hosts and demonstrating the operational value of LLMs for low-skill adversaries.

Why This Matters

Publisher reporting describes a security event affecting for. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.

Recommended Action

Confirm whether for is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

May 18, 2026 12:30

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

Synack2026 State of Vulnerabilities ReportRemote Code ExecutionSupply ChainExploitGenerated Malware Used

Authoritative Intelligence

CVE CVE-2025-55182 Incident identifier

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Public GitHub References

Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ€” it does not fetch or display exploit code.

CVE-2025-55182: 6 public repository references found.

msanft/CVE-2025-55182

Possible public PoC reference

Explanation and full RCE PoC for CVE-2025-55182

1429 stars ยท Python

Open repository
lachlan2k/React2Shell-CVE-2025-55182-original-poc

Possible public PoC reference

Original Proof-of-Concepts for React2Shell CVE-2025-55182

1062 stars ยท JavaScript

Open repository
ejpir/CVE-2025-55182-research

Possible public PoC reference

CVE-2025-55182 POC

792 stars ยท JavaScript

Open repository
emredavut/CVE-2025-55182

Possible public PoC reference

RSC/Next.js RCE Vulnerability Detector & PoC Chrome Extension โ€“ CVE-2025-55182 & CVE-2025-66478

314 stars ยท JavaScript

Open repository
whiteov3rflow/CVE-2025-55182-poc

Possible public PoC reference

React2Shell Proof of Concept

92 stars ยท Python

Open repository
l4rm4nd/CVE-2025-55182

Possible public PoC reference

Docker poc lab for CVE-2025-55182 / CVE-2025-66478 (React2Shell) detection and exploitation

88 stars ยท JavaScript

Open repository

A public PoC or exploit-related repository means weaponization material may exist in the open. It does not prove your environment was targeted.

Timeline

  • Incident first seen
    Feb 10, 2026 05:30

    BugSkan first recorded this incident.

  • AI/LLM-Generated Malware Used to Exploit React2Shell - Darktrace
    Feb 10, 2026 05:30

    darktrace.com ยท Malware

  • AI shrinks vulnerability exploitation window to hours - Help Net Security
    May 18, 2026 12:30

    news.google.com ยท Vulnerability

  • Latest observed development
    May 18, 2026 12:30

    Most recent source or update associated with this incident.

Sources

AI/LLM-Generated Malware Used to Exploit React2Shell - Darktrace

darktrace.com ยท Feb 10, 2026 05:30

An AI-generated malware sample exploited CVE-2025-55182, known as React2Shell, within a Docker honeypot with an exposed daemon. This resulted in remote code execution, allowing the deployment of an XMRig cryptominer on over ninety compromised hosts and demonstrating the operational value of LLMs for low-skill adversaries.

Open publisher source
AI shrinks vulnerability exploitation window to hours - Help Net Security

news.google.com ยท May 18, 2026 12:30

AI shrinks vulnerability exploitation window to hours Help Net Security

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

โ† Back to incident intelligence