216.73.217.22

Critical React Native Metro dev server bug under attack

· Published 04/02/2026 11:13 · Modified 05/02/2026 11:22

Export JSON

Essential information

Published
04/02/2026 11:13
Modified
05/02/2026 11:22
Tags
2026-02-04 CVE-2025-11953 exploit linux malware delivery metro dev server os command injection react native windows
Related entities
1 vulnerabilities (cve), 1 observables, 5 techniques (mitre)

Description

A critical vulnerability in 's Metro development server is being actively exploited to deliver malware to and machines. The flaw, tracked as , allows unauthenticated attackers to execute arbitrary commands through . Researchers discovered exploitation attempts as early as December, with attacks disabling Microsoft Defender protections and delivering a Rust-based payload with anti-analysis features. Despite its severity and ongoing exploitation, the vulnerability has not received widespread public acknowledgment. The bug affects the Community command line tool, a popular npm package with millions of weekly downloads, highlighting the potential impact on developer tooling and the need for increased awareness and security measures.

External references