logo

NPM Supply Chain Attack Compromises 16 Popular React Native and GlueStack Packages (Campaign)

ID: 104909f0-cd67-5887-ad62-7f424bdc4d01

STIX ID: report--104909f0-cd67-5887-ad62-7f424bdc4d01

Feed Name: Wiz Cloud Threat Landscape

Threat Score
88/100

Date Published: 2025-06-07

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

A threat actor compromised 16 widely used React Native and GlueStack packages (collectively downloaded over a million times weekly) by inserting a whitespace-obfuscated remote access trojan (RAT). The malicious payload supports arbitrary command execution, file uploads, data exfiltration, installs dependencies (axios, socket.io-client), implements version-based switching of hardcoded C2 servers, includes new commands (ss_info for system metadata and ss_ip for external IP reporting), and adds persistence mechanisms targeting Windows paths.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.