Hackers Exploiting React Native’s Metro Server in the Wild to Attack Developers
ID: 339d9abc-8bf2-503a-8092-8c6178592d9c
STIX ID: report--339d9abc-8bf2-503a-8092-8c6178592d9c
Feed Name: cybersecurityNews.com
Threat Score
VulnCheck detected operational exploitation of CVE-2025-11953 (Metro4Shell) in React Native’s Metro Development Server beginning December 2025; attackers abused an /open-url OS command injection to deliver a multi-stage PowerShell loader and UPX-packed Rust payloads across Windows and Linux, with IOCs and mitigations (upgrade to @react-native-community/cli >= 20.0.0) provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
