logo

Backdoored React Native Packages Target Developers with Crypto-Stealing Malware

ID: be67ca9d-acc6-5507-9e4a-bffde174355b

STIX ID: report--be67ca9d-acc6-5507-9e4a-bffde174355b

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-03-16

Date Updated: 2026-04-23

Author: Ddos

...
...

Aikido researchers disclosed a coordinated supply-chain attack on March 16, 2026 where the publisher “AstrOOnauta” released backdoored updates to react-native-country-select and react-native-international-phone-number; the packages included a malicious preinstall hook that automatically downloads and runs a multi-stage Windows credential and crypto stealer upon npm install, targeting browser wallets, browser profile data, and developer credentials (npm/GitHub), establishing persistence and exfiltrating collected archives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.