#React2Shell

Vulnerability/Target

2025-12-08 • EtherRAT: DPRK uses novel Ethereum implant in React2Shell attacks

React2Shell is a remote-code-execution vulnerability in React Server Components that affected applications including Next.js deployments. Suspected DPRK-linked operators exploited it against cryptocurrency staking platforms and deployed EtherRAT, a persistent implant that used Ethereum smart contracts for command-and-control resolution and established multiple Linux persistence mechanisms.

Tagged Reports

« Back