logo

Hackers Exploit Metro4Shell RCE Flaw in React Native CLI npm Package

ID: f9d7dbb0-cebc-52f5-a001-11df64cd3002

STIX ID: report--f9d7dbb0-cebc-52f5-a001-11df64cd3002

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-02-03

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Threat actors are actively exploiting CVE-2025-11953 (Metro4Shell) in the @react-native-community/cli Metro Development Server to achieve unauthenticated remote code execution; observed activity delivered a Base64 PowerShell loader that configures Microsoft Defender exclusions, downloads and executes a Rust-based payload with anti-analysis checks, and uses raw TCP C2 (observed IPs: 5.109.182.231, 223.6.249.141, 134.209.69.155). VulnCheck observed exploitation beginning December 21, 2025, and CISA added the vulnerability to its KEV catalog on February 5, 2026, requiring remediation for federal agencies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.