Malicious GitHub Scanner for React2Shell CVE-2025-55182 Discovered

Malicious GitHub Scanner for React2Shell CVE-2025-55182 Discovered

First seen 16 Dec 2025, 17:57 UTC HackreadHow2ShoutScworld 36.2

Article Content

Browse articles
ThreatCluster

A GitHub repository masquerading as a vulnerability scanner for CVE-2025-55182, known as 'React2Shell', has been identified as a source of malware. The fake tool executes mshta.exe to deliver a malicious payload, impacting users who download it under the guise of a security tool.