logo

Active NPM Attack Escalates: 16 React Native Packages for GlueStack Backdoored Overnight

ID: c02bacb7-ab79-5f7a-987d-960e2b72a23f

STIX ID: report--c02bacb7-ab79-5f7a-987d-960e2b72a23f

Feed Name: Aikido Security's Blog

Threat Score
85/100

Date Published: 2025-06-07

Date Updated: 2026-07-24

...
...

On 6–7 June 2025 a threat actor compromised numerous popular npm packages (combined >1M weekly downloads) by publishing versions containing an obfuscated Node.js Remote Access Trojan. The report provides the original obfuscated payload and a deobfuscated variant, details of new C2 servers (136.0.9.8 and 85.239.62.36), RAT commands (including ss_info and ss_ip), persistence behavior, and a full list of package/version indicators to check.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.