Hackers exploit critical React Native Metro bug to breach dev systems
ID: 71a35c71-0afa-5865-8c34-ef267b53ebc3
STIX ID: report--71a35c71-0afa-5865-8c34-ef267b53ebc3
Feed Name: Bleeping Computer
Researchers observed active exploitation of CVE-2025-11953 (Metro4Shell) in the React Native Metro server, with attackers sending POST requests to the /open-url endpoint to deliver base64-encoded PowerShell payloads that disable Defender exclusions, retrieve platform-specific binaries from attacker infrastructure, write them to disk, and execute them; both Windows and Linux payloads (including a Rust UPX-packed Windows binary) were delivered, IoCs were published, and roughly 3,500 Metro servers remain exposed online.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
