React2Shell Exploitation Now Turns Into Credential Theft Fast

The useful shift is not that React2Shell was exploited. It is that China-nexus crews moved from fresh RCE to credential theft in less than a day, which leaves defenders with less time than many teams need just to confirm exposure. Once the code execution lands, the fight shifts from patching a flaw to containing an identity compromise. CrowdStrike tied that pace to Vault Panda and Genesis Panda, who used the React2Shell bug in React Server Components and Next.js applications and then dropped RATs for post-exploit credential harvesting. The same report says 88% of publicly disclosed exploited flaws in H1 2026 were hit within 48 hours, so disclosure-day and secret hygiene now belong in the same response window.

Part of the PlainSec briefing for 2026-08-03

Every edition of this story: React2Shell Exploitation Now Turns Into Credential Theft Fast

Sources