Crypto Wallets Targeted In JavaScript Library Exploit—Cybersecurity Firm
A critical vulnerability in React Server Components, tracked as CVE-2025-55182, is being exploited to inject malicious code into live websites, siphoning cryptocurrency from connected wallets. The flaw, disclosed by the React team on December 3, carries a maximum severity rating.
Cybersecurity firm Security Alliance (SEAL) confirms active targeting of multiple crypto websites. Attackers leverage the bug to execute arbitrary code on affected servers, enabling wallet-draining campaigns. Patched releases (19.0.1, 19.1.2, 19.2.1) are available for React Server Components versions 19.0 through 19.2.0.
The exploit abuses unsafe deserialization in the Flight protocol, allowing a single crafted HTTP request to compromise web servers. SEAL urges immediate front-end code reviews to detect suspicious assets.