Threat · curated 1 Aug 2026
AI/LLM-Generated Malware Used to Exploit React2Shell
First reported darktrace.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
AI/LLM-generated malware observed exploiting CVE-2025-55182 in the wild signals that LLM-assisted development is lowering the skill barrier for attackers to build effective exploitation tools quickly.
Darktrace reports observing a fully AI/LLM-generated malware sample in its CloudyPots honeypot network exploiting the React2Shell vulnerability (CVE-2025-55182). The analysis argues that LLM-assisted development ('vibecoding') is enabling low-skill attackers to rapidly produce functional exploitation tooling against internet-facing infrastructure.