The @cloudflare.social threat intelligence team have published this great blog with a really detailed breakdown on the exploitation activity against React and Next.js. Some massive numbers of attempts, as well as confident attribution of the attacks as mostly coming from Chinese state actors.
blog.cloudflare.com
React2Shell and related RSC vulnerabilities threat brief- early exploitation activity and threat actor techniques
Early activity indicates that threat actors quickly integrated this vulnerability into their scanning and reconnaissance routines and targeted critical infrastructure including nuclear fuel, uranium a...