logo

Hackers Actively Exploit React Native Metro Server to Target Software Developers

ID: 3c5ed0d6-9935-5899-8bda-218e5c84cfc6

STIX ID: report--3c5ed0d6-9935-5899-8bda-218e5c84cfc6

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-02-04

Date Updated: 2026-04-22

Author: Divya

...
...

A critical RCE vulnerability in React Native's Metro server (CVE-2025-11953, “Metro4Shell”) is being actively exploited to deploy multi-stage malware against developer machines; VulnCheck observed sustained attacks beginning December 2025 and provided IOCs (exploitation source IPs, payload hosting servers, and SHA-256 hashes). The exploit abuses an unsafe /open-url endpoint to execute arbitrary commands, affects @react-native-community/cli-server-api versions 4.8.0 through 20.0.0-alpha.2 (patched in 20.0.0+), and leverages PowerShell loaders and UPX-packed Rust binaries with anti-analysis techniques to evade detection, while roughly 3,500 Metro servers remain internet-exposed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.