A severe React Server Components vulnerability (CVE-2025-55182, CVSS 10) is being actively exploited to inject malicious code into crypto-related websites, compromise and take over servers, siphon funds from wallets and deploy cryptomining software. The campaign has prompted urgent patches across major React-based frameworks.