Glassworm Strikes Popular React Native Phone Number Packages
ID: c6fd205d-19f3-5e7c-be50-4f98f3f93751
STIX ID: report--c6fd205d-19f3-5e7c-be50-4f98f3f93751
Feed Name: Aikido Security's Blog
On March 16, 2026, two React Native npm packages from the AstrOOnauta publisher ([email protected] and [email protected]) were backdoored via identical `preinstall` hooks that fetch a staged payload (via a Solana memo + remote hosts) and ultimately deploy a Windows-focused credential and crypto wallet stealer that establishes persistence, downloads additional components (including a Node runtime), and exfiltrates data to attacker-controlled IPs/domains; the report includes SHA-256, IPs, domains, and behavioral indicators for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
