logo

Hackers exploit critical React Native Metro bug to breach dev systems

ID: 71a35c71-0afa-5865-8c34-ef267b53ebc3

STIX ID: report--71a35c71-0afa-5865-8c34-ef267b53ebc3

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-02-03

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Researchers observed active exploitation of CVE-2025-11953 (Metro4Shell) in the React Native Metro server, with attackers sending POST requests to the /open-url endpoint to deliver base64-encoded PowerShell payloads that disable Defender exclusions, retrieve platform-specific binaries from attacker infrastructure, write them to disk, and execute them; both Windows and Linux payloads (including a Rust UPX-packed Windows binary) were delivered, IoCs were published, and roughly 3,500 Metro servers remain exposed online.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.