Surviving a Zero-Day React2Shell Attack & 100% CPU Recovery Under Live Traffic
Regaining root control, purging malware persistence, and restoring Pro Trainer IT & SubsDrop with zero data loss.
The Operational Challenge
Our production Linux VPS suddenly became unresponsive with CPU, RAM, and disk I/O pinned at 100% (normal baseline is 15-20%). Even standard SSH logins were hanging. At the time, both Pro Trainer IT and SubsDrop were co-located on this host. With hundreds of active students trying to stream classes and customers attempting checkout on SubsDrop, furious error tickets flooded in. Our core services were completely suffocating.
Architectural Resolution & Implementation
Accessed the server via out-of-band VNC rescue console. Through process inspection and socket analysis, discovered an active Remote Code Execution (RCE) intrusion via the React2Shell vulnerability (CVE-2025-55182) that had spawned an unauthorized cryptominer and hidden persistence scripts in /tmp and cron. Killed malicious process trees, removed unauthorized cronjobs and root SSH keys, patched vulnerable packages, isolated SubsDrop and Pro Trainer IT into separate Docker containers with strict CPU/memory limits, hardened the UFW firewall, and brought both production services back online with zero database loss.