logo

Critical React Native Metro dev server bug under attack as researchers scream into the void

ID: 98761c0b-7a13-580f-9cb8-b2bd3701edd3

STIX ID: report--98761c0b-7a13-580f-9cb8-b2bd3701edd3

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2026-02-03

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A critical command-injection vulnerability (CVE-2025-11953) in the React Native Community Metro development server is being actively exploited in the wild to deliver multi-stage malware to Windows and Linux systems. Researchers observed attacks starting in December that used a PowerShell-based loader to disable Microsoft Defender and fetch Rust-based binaries with anti-analysis features; proof-of-concept code and multiple payload-hosting IPs were identified, and the flaw affects a widely used npm package.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.