Crypto Wallets Targeted In JavaScript Library Exploit—Cybersecurity Firm

bitcoinist2025-12-16 tarihinde yayınlandı2025-12-16 tarihinde güncellendi

Özet

A critical vulnerability (CVE-2025-55182) in React Server Components (versions 19.0 to 19.2.0) is being actively exploited to inject malicious code into websites and steal cryptocurrency from connected wallets. The flaw, which allows unauthenticated attackers to execute arbitrary code on affected servers, has led to wallet-draining campaigns across multiple crypto sites. Cybersecurity firm Security Alliance (SEAL) warns that attackers are using the exploit to inject scripts that hijack or redirect transactions by altering user interfaces or swapping addresses. Over 50 organizations have reported compromise attempts, with scanning tools and exploit kits rapidly spreading in underground forums. Patched versions (19.0.1, 19.1.2, 19.2.1) are available, and all affected sites are urged to update immediately.

A critical flaw in React Server Components is being used by attackers to inject malicious code into live websites, and that code is siphoning crypto from connected wallets.

Reports note that the vulnerability, tracked as CVE-2025-55182, was published by the React team on December 3 and carries a maximum severity rating.

Cybersecurity firm Security Alliance (SEAL) has confirmed that multiple crypto websites are actively being targeted, and they urge operators to review all React Server Components immediately to prevent wallet-draining attacks.

Security teams say the bug allows an unauthenticated attacker to run code on affected servers, which has been turned into wallet-draining campaigns across several sites.

Image: Shutterstock

A Wide Risk To Sites Using Server Components

SEAL said the flaw affects React Server Components packages in versions 19.0 through 19.2.0, and patched releases such as 19.0.1, 19.1.2, and 19.2.1 were issued after disclosure.

The vulnerability works by exploiting unsafe deserialization in the Flight protocol, letting a single crafted HTTP request execute arbitrary code with the web server’s privileges. Security teams have warned that many sites using default configurations are at risk until they apply the updates.

Attackers Inject Wallet-Draining Scripts Into Compromised Pages

According to industry posts, threat actors are using the exploit to plant scripts that prompt users to connect Web3 wallets and then hijack or redirect transactions.

In some cases the injected code alters the user interface or swaps addresses, so a user believes they are sending funds to one account while the transaction actually pays an attacker. This method can hit users who trust familiar crypto sites and connect wallets without checking every approval.

BTCUSD now trading at $89,626. Chart: TradingView

Scanners And Proof-Of-Concepts Flooded Underground Forums

Security researchers report a rush of scanning tools, fake proof-of-concept code, and exploit kits shared in underground forums shortly after the vulnerability was disclosed.

Cloud and threat-intelligence teams have observed multiple groups scanning for vulnerable servers and testing payloads, which has accelerated active exploitation.

Some defenders say that the speed and volume of scanning have made it hard to stop all attempts before patches are applied.

More Than 50 Organizations Reported Compromise Attempts

Based on reports from incident responders, post-exploitation crypto activity has been observed at more than 50 organizations across finance, media, government, and tech.

In several investigations, attackers established footholds and then used those to deliver further malware or to seed front-end code that targets wallet users.

SEAL has emphasized that organizations failing to patch or monitor their servers could experience further attacks, and ongoing monitoring is essential until all systems are verified safe.

Featured image from Unsplash, chart from TradingView

İlgili Okumalar

Breaking News: Full Detailed Rationale and Explanation of the Fed's Interest Rate Decision Released!

As expected, the Federal Reserve kept its key interest rate unchanged at 3.50-3.75 percent, marking the fifth consecutive meeting without a rate change. The Federal Open Market Committee's (FOMC) decision passed with a 9-3 majority vote. Cleveland Fed President Loretta Mester, Minneapolis Fed President Neel Kashkari, and Dallas Fed President Lorie Logan dissented, voting in favor of a 25 basis point rate hike. This was the first meeting since 2016 where three regional Fed presidents voted against holding rates steady, signaling growing influence among members advocating for tighter monetary policy to combat inflation. The Fed's statement noted that economic activity has been expanding at a solid pace despite high uncertainty, partly due to Middle East conflicts. It highlighted that growth in productivity and investment remained strong, employment gains have aligned with labor force growth, and the unemployment rate has remained relatively stable. The Fed also committed to maintaining ample reserves in the banking system. The statement emphasized that inflation remains above the Fed's 2% target. It noted that supply shocks, including in the energy sector, are adding to inflationary pressures. The Committee stated it will continue to closely monitor incoming data and risks in pursuit of its price stability goal. The dissenting members argued that the target range for the federal funds rate should have been increased by 25 basis points.

cryptonews.ru8 dk önce

Breaking News: Full Detailed Rationale and Explanation of the Fed's Interest Rate Decision Released!

cryptonews.ru8 dk önce

The Fed's Interest Rate Decision is Inevitable! Former Senior Fed Advisor Reveals His Forecast for Today!

Former Federal Reserve senior advisor John Faust stated he does not expect the Fed to raise interest rates at the FOMC meeting concluding today. He argued the Fed will not try to win credibility by deliberately surprising markets. In his assessment, Faust noted that Fed Chairman Kevin Warsh has used strong rhetoric on restoring price stability but largely failed to share details on how he plans to achieve it. This information gap has led to various market scenarios. However, Faust believes the reality is simpler: Warsh positions himself as a pragmatic, tough-minded policymaker, placing high importance on monetary policy communication while showing flexibility regarding balance sheet reduction. Faust compared Warsh's approach to the "refined intuitive approach" used by former Chairman Alan Greenspan. Faust stated that, unlike strict policy rules, this approach does not yield clear-cut answers on rate decisions. In current conditions, both a 25-basis-point hike and waiting for the next meeting could be reasonably justified. Aligning with market expectations, Faust predicts the Fed will choose to wait today. He believes the benefit of waiting outweighs the negatives, partly because he agrees that deliberately surprising markets to boost credibility is not a valid factor. Faust also argued there is no substantial macroeconomic difference between hiking today and holding steady, as a 25-basis-point move over eight weeks alone is not economically decisive. He emphasized that the important aspect will not be the decision itself, but how it is explained to markets. Warsh has so far advocated forward-looking policy without clear guidance on economic forecasts or the likely rate path. Faust warned that if the Fed does not explicitly state grounds for a hike and opts to wait for more data, markets may misinterpret the decision's meaning. Regardless of today's outcome, how Warsh explains the policy decisions at the meeting and press conference may be the most critical information for investors.

cryptonews.ru42 dk önce

The Fed's Interest Rate Decision is Inevitable! Former Senior Fed Advisor Reveals His Forecast for Today!

cryptonews.ru42 dk önce

İşlemler

Spot
活动图片