Active NPM Attack Escalates: 16 React Native Packages for GlueStack Backdoored Overnight
ID: c02bacb7-ab79-5f7a-987d-960e2b72a23f
STIX ID: report--c02bacb7-ab79-5f7a-987d-960e2b72a23f
Feed Name: Aikido Security's Blog
Threat Score
On 6–7 June 2025 a threat actor compromised numerous popular npm packages (combined >1M weekly downloads) by publishing versions containing an obfuscated Node.js Remote Access Trojan. The report provides the original obfuscated payload and a deobfuscated variant, details of new C2 servers (136.0.9.8 and 85.239.62.36), RAT commands (including ss_info and ss_ip), persistence behavior, and a full list of package/version indicators to check.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
