Trade Haven Hub - Investing and Stock News
  • Investment Tips
  • Trade Tips
  • Crypto News
  • Economy News
  • Stock Market
  • Investment Tips
  • Trade Tips
  • Crypto News
  • Economy News
  • Stock Market
No Result
View All Result
Trade Haven Hub - Investing and Stock News
No Result
View All Result
Home Crypto News

Major JavaScript Library Breach Puts All Crypto Websites at Risk

by
December 15, 2025
in Crypto News
0
Major JavaScript Library Breach Puts All Crypto Websites at Risk
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

A critical security flaw in React Server Components has prompted urgent warnings across the crypto industry, as threat actors are rapidly exploiting it to drain wallets and deploy malware.

Security Alliance announced that crypto-drainers are actively weaponizing CVE-2025-55182, urging all websites to review their front-end code immediately for suspicious assets.

The vulnerability affects not only Web3 protocols but all websites using React, with attackers targeting permit signatures across platforms.

Users face immediate risk when signing any transaction, as malicious code intercepts wallet communications and redirects funds to attacker-controlled addresses.

Crypto Drainers using React CVE-2025-55182

We are observing a big uptick in drainers uploaded to legitimate (crypto) websites through exploitation of the recent React CVE.

All websites should review front-end code for any suspicious assets NOW.

— Security Alliance (@_SEAL_Org) December 13, 2025

Critical Flaw Enables Remote Code Execution

React’s official team disclosed CVE-2025-55182 on December 3, rating it CVSS 10.0 following Lachlan Davidson’s November 29 report through Meta Bug Bounty.

The unauthenticated remote code execution vulnerability exploits how React decodes payloads sent to Server Function endpoints, allowing attackers to craft malicious HTTP requests that execute arbitrary code on servers.

The flaw impacts React versions 19.0, 19.1.0, 19.1.1, and 19.2.0 across react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack packages.

Major frameworks, including Next.js, React Router, Waku, and Expo, require immediate updates. Patches arrived in versions 19.0.1, 19.1.2, and 19.2.1, with Next.js users needing upgrades across multiple release lines from 14.2.35 through 16.0.10.

Unfortunately, the researchers have again detected two major new flaws.

Researchers have found two new vulnerabilities in React Server Components while attempting to exploit the patches last week.

These are new issues, separate from the critical CVE last week. The patch for React2Shell remains effective for the Remote Code Execution exploit.

— React (@reactjs) December 11, 2025

Vercel deployed Web Application Firewall rules to automatically protect projects on its platform, though the company emphasized that WAF protection alone remains insufficient.

“Immediate upgrades to a patched version are required,” Vercel stated in its December 3 security bulletin, adding that the vulnerability affects applications that process untrusted input in ways that permit remote code execution.

Multiple Threat Groups Launch Coordinated Attacks

Google Threat Intelligence Group documented widespread attacks beginning on December 3, tracking criminal groups ranging from opportunistic hackers to government-backed operations.

Chinese hacking groups installed various malware types on compromised systems, primarily targeting cloud servers on Amazon Web Services and Alibaba Cloud.

These attackers employed sophisticated techniques to maintain long-term access to victim systems.

Some groups installed software creating secret tunnels for remote control, while others deployed programs that continuously download additional malicious tools disguised as legitimate files. The malware hides in system folders and automatically restarts to avoid detection.

Several groups disguised malicious software as common programs or used legitimate cloud services, such as Cloudflare Pages and GitLab, to hide their communications.

New details on multiple state and criminal actors now exploiting React2Shell. https://t.co/4M21rqLndT

— John Hultquist (@JohnHultquist) December 13, 2025

Financially motivated criminals joined the attack wave starting on December 5, installing crypto-mining software that secretly uses victims’ computing power to generate Monero.

These miners run constantly in the background, driving up electricity costs while generating profits for attackers. Underground hacking forums quickly filled with discussions sharing attack tools and exploitation experiences.

Historic Supply Chain Attack Pattern Continues

The React vulnerability follows a September 8 attack in which hackers compromised Josh Goldberg’s npm account and published malicious updates to 18 widely used packages, including chalk, debug, and strip-ansi.

These utilities collectively account for over 2.6 billion weekly downloads, and researchers have discovered crypto-clipper malware that intercepts browser functions to swap legitimate wallet addresses with attacker-controlled ones.

Ledger CTO Charles Guillemet described that incident as a “large-scale supply chain attack,” advising users without hardware wallets to avoid on-chain transactions.

The attackers gained access through phishing campaigns impersonating npm support, claiming accounts would be locked unless two-factor authentication credentials were updated by September 10.

Hackers are stealing more crypto and moving it faster. One laundering process took only 2 minutes 57 seconds. Can the industry cope?#CryptoSecurity #Web3 #Blockchain #DeFihttps://t.co/lGwutYsT6Q

— Cryptonews.com (@cryptonews) August 12, 2025

Global Ledger data shows hackers stole over $3 billion across 119 incidents in the first half of 2025, with 70% of breaches involving funds being moved before they became public.

Only 4.2% of stolen assets were recovered, as laundering now takes seconds rather than hours.

For now, organizations using React or Next.js are advised to patch immediately to versions 19.0.1, 19.1.2, or 19.2.1, deploy WAF rules, audit all dependencies, monitor network traffic for wget or cURL commands initiated by web server processes, and hunt for unauthorized hidden directories or malicious shell configuration injections.

The post Major JavaScript Library Breach Puts All Crypto Websites at Risk appeared first on Cryptonews.

Previous Post

Uranium Price Forecast: Top Trends for Uranium in 2026

Next Post

Hex Trust’s High-Stakes Wrapped XRP Gambit: $100M Liquidity Infusion Fuels Bridge Exploit Fears

Next Post
Hex Trust’s High-Stakes Wrapped XRP Gambit: $100M Liquidity Infusion Fuels Bridge Exploit Fears

Hex Trust’s High-Stakes Wrapped XRP Gambit: $100M Liquidity Infusion Fuels Bridge Exploit Fears

  • Trending
  • Comments
  • Latest
Buy Bitcoin Under $100K Before The Next Bull Run

Buy Bitcoin Under $100K Before The Next Bull Run

April 22, 2025
Zeldin, McCain hammer Crockett on Epstein donations claim

Zeldin, McCain hammer Crockett on Epstein donations claim

November 20, 2025
Best Altcoin Coin to Buy During the Crypto Crash – 21 November

Best Altcoin Coin to Buy During the Crypto Crash – 21 November

November 22, 2025
Target is eliminating 1,800 corporate jobs as it looks to reclaim its lost luster

Target is eliminating 1,800 corporate jobs as it looks to reclaim its lost luster

October 24, 2025
Bitcoin Could Hit $140,000 in Next 180 Days, Expert Says

Bitcoin Could Hit $140,000 in Next 180 Days, Expert Says

0
Quantum Computing: its Evolution and its Potential Future

Quantum Computing: its Evolution and its Potential Future

0
Quantum Computing: its Evolution and its Potential Future

Quantum Computing: its Evolution and its Potential Future

0
Air Direct Capture – Reducing CO2 from the Atmosphere

Air Direct Capture – Reducing CO2 from the Atmosphere

0
Bitcoin Could Hit $140,000 in Next 180 Days, Expert Says

Bitcoin Could Hit $140,000 in Next 180 Days, Expert Says

December 15, 2025
Do Kwon Could Face Second Trial in Korea After 15-Year US Sentence

Do Kwon Could Face Second Trial in Korea After 15-Year US Sentence

December 15, 2025
Hex Trust’s High-Stakes Wrapped XRP Gambit: $100M Liquidity Infusion Fuels Bridge Exploit Fears

Hex Trust’s High-Stakes Wrapped XRP Gambit: $100M Liquidity Infusion Fuels Bridge Exploit Fears

December 15, 2025
Major JavaScript Library Breach Puts All Crypto Websites at Risk

Major JavaScript Library Breach Puts All Crypto Websites at Risk

December 15, 2025

    Stay updated with the latest news, exclusive offers, and special promotions. Sign up now and be the first to know! As a member, you'll receive curated content, insider tips, and invitations to exclusive events. Don't miss out on being part of something special.


    By opting in you agree to receive emails from us and our affiliates. Your information is secure and your privacy is protected.

    Recent News

    Bitcoin Could Hit $140,000 in Next 180 Days, Expert Says

    Bitcoin Could Hit $140,000 in Next 180 Days, Expert Says

    December 15, 2025
    Do Kwon Could Face Second Trial in Korea After 15-Year US Sentence

    Do Kwon Could Face Second Trial in Korea After 15-Year US Sentence

    December 15, 2025
    Hex Trust’s High-Stakes Wrapped XRP Gambit: $100M Liquidity Infusion Fuels Bridge Exploit Fears

    Hex Trust’s High-Stakes Wrapped XRP Gambit: $100M Liquidity Infusion Fuels Bridge Exploit Fears

    December 15, 2025
    Major JavaScript Library Breach Puts All Crypto Websites at Risk

    Major JavaScript Library Breach Puts All Crypto Websites at Risk

    December 15, 2025
    • About us
    • Contact us
    • Privacy Policy
    • Terms & Conditions

    Copyright © 2025 tradehavenhub.com | All Rights Reserved

    No Result
    View All Result
    • Investment Tips
    • Trade Tips
    • Crypto News
    • Economy News
    • Stock Market

    Copyright © 2025 tradehavenhub.com | All Rights Reserved