logo

Hackers exploit critical React Native Metro bug to breach dev systems

ID: 1923e985-dade-599e-b419-80fad0d56984

STIX ID: report--1923e985-dade-599e-b419-80fad0d56984

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-02-03

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers observed active exploitation of CVE-2025-11953 (dubbed Metro4Shell) in the React Native Metro server: attackers send POST requests to the /open-url endpoint to deliver base64-encoded PowerShell payloads that disable Defender, retrieve and drop UPX-packed Rust binaries for Windows and corresponding Linux binaries, and execute them; VulnCheck reported repeated activity, researchers published IoCs, and scans show roughly 3,500 exposed Metro servers online.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.