Hackers abused React Native CLI flaw to deploy Rust malware before public disclosure
ID: 958d6d65-501f-52d4-850f-e1a0da62b6b5
STIX ID: report--958d6d65-501f-52d4-850f-e1a0da62b6b5
Feed Name: Security Affairs
Threat Score
A critical command-injection flaw (CVE-2025-11953, "Metro4Shell") in the React Native CLI Metro dev server is being actively exploited in the wild to run arbitrary commands and deploy a UPX-packed Rust malware via a multi-stage PowerShell loader; researchers observed sustained exploitation weeks before broad disclosure and published IoCs including exploitation sources and payload hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
