Skip to content
Malicious GitHub Scanner for React2Shell CVE-2025-55182 Discovered

Malicious GitHub Scanner for React2Shell CVE-2025-55182 Discovered

First seen 16 Dec 2025, 17:57 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A GitHub repository masquerading as a vulnerability scanner for CVE-2025-55182, known as 'React2Shell', has been identified as a source of malware. The fake tool executes mshta.exe to deliver a malicious payload, impacting users who download it under the guise of a security tool.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (3)

Following this threat?

Track PyStoreRAT and CVE-2025-55182 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed