Threat · curated 1 Aug 2026

AI/LLM-Generated Malware Used to Exploit React2Shell

Coverage timeline

1 Aug 2026darktrace.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

AI/LLM-generated malware observed exploiting CVE-2025-55182 in the wild signals that LLM-assisted development is lowering the skill barrier for attackers to build effective exploitation tools quickly.

Darktrace reports observing a fully AI/LLM-generated malware sample in its CloudyPots honeypot network exploiting the React2Shell vulnerability (CVE-2025-55182). The analysis argues that LLM-assisted development ('vibecoding') is enabling low-skill attackers to rapidly produce functional exploitation tooling against internet-facing infrastructure.