Hackers exploit critical React Native Metro bug to breach dev systems
ID: 1923e985-dade-599e-b419-80fad0d56984
STIX ID: report--1923e985-dade-599e-b419-80fad0d56984
Feed Name: Bleeping Computer
Threat Score
Researchers observed active exploitation of CVE-2025-11953 (dubbed Metro4Shell) in the React Native Metro server: attackers send POST requests to the /open-url endpoint to deliver base64-encoded PowerShell payloads that disable Defender, retrieve and drop UPX-packed Rust binaries for Windows and corresponding Linux binaries, and execute them; VulnCheck reported repeated activity, researchers published IoCs, and scans show roughly 3,500 exposed Metro servers online.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
