logo

A deeper look into the threat actor behind the react-native-aria attack

ID: 1df9bb18-f022-574d-93e0-e75287dce4a9

STIX ID: report--1df9bb18-f022-574d-93e0-e75287dce4a9

Feed Name: Aikido Security's Blog

Threat Score
75/100

Date Published: 2025-06-12

Date Updated: 2026-07-24

...
...

This report documents an active supply-chain campaign where a threat actor compromised multiple npm packages and GitHub repositories to distribute a Node.js remote-access trojan. The malware leverages obfuscation, dynamic dependency installation, C2 servers, and a novel blockchain-based staging mechanism (Aptos + BSC) to retrieve and execute hidden payloads; included are deobfuscated code extracts, sandbox findings, and indicators such as package names, blockchain addresses, and a C2 IP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.