Skip to content

Conversation

@nasbench
Copy link
Contributor

@nasbench nasbench commented Dec 8, 2025

This PR adds 2 new analytics covering the React2Shell vulnerability. The 2 analytics are designed to look for suspicious child processes of node with specific command-line strings indicative of react / next.js apps.

It also adds a corresponding analytic story.

I have put together some notes explaining the reasoning behind the choice of certain strings and the logic. See React-Next-Child-Processes-Notes

New Analytics

  • Linux Suspicious React or Next.js Child Process
  • Windows Suspicious React or Next.js Child Process

New Analytic Story

  • React2Shell

@nasbench nasbench changed the title React2shell Analytics React2Shell Analytics Dec 8, 2025
@nasbench nasbench marked this pull request as ready for review December 8, 2025 12:03
@nasbench nasbench added this to the v5.19.0 milestone Dec 8, 2025
Copy link
Contributor

@ljstella ljstella left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

:shipit:

@nasbench nasbench merged commit 5d7c65d into develop Dec 8, 2025
4 checks passed
@nasbench nasbench deleted the react-stuff branch December 8, 2025 14:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants