logo

Hackers Exploiting React Native’s Metro Server in the Wild to Attack Developers

ID: 339d9abc-8bf2-503a-8092-8c6178592d9c

STIX ID: report--339d9abc-8bf2-503a-8092-8c6178592d9c

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-02-03

Date Updated: 2026-04-21

Author: Guru Baran

...
...

VulnCheck detected operational exploitation of CVE-2025-11953 (Metro4Shell) in React Native’s Metro Development Server beginning December 2025; attackers abused an /open-url OS command injection to deliver a multi-stage PowerShell loader and UPX-packed Rust payloads across Windows and Linux, with IOCs and mitigations (upgrade to @react-native-community/cli >= 20.0.0) provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.