between the ~1,400 networks we've seen exploiting React2Shell (CVE-2025-55182) we've captured about 100 different distinct malware payloads. Lots of vibe coded slop, coin miners, chinese comments, mirai variants, etc. hit us up if you're tracking this and want deets research@greynoise.io