logo

Hackers abused React Native CLI flaw to deploy Rust malware before public disclosure

ID: 958d6d65-501f-52d4-850f-e1a0da62b6b5

STIX ID: report--958d6d65-501f-52d4-850f-e1a0da62b6b5

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

A critical command-injection flaw (CVE-2025-11953, "Metro4Shell") in the React Native CLI Metro dev server is being actively exploited in the wild to run arbitrary commands and deploy a UPX-packed Rust malware via a multi-stage PowerShell loader; researchers observed sustained exploitation weeks before broad disclosure and published IoCs including exploitation sources and payload hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.