Threat actors have been observed exploiting CVE-2025-11953 (aka Metro4Shell), a critical RCE flaw (CVSS 9.8) in the React Native Metro Development Server exposed via the @react-native-community/cli / @react-native-community/cli-server-api npm packages. The issue stems from Metro’s development-only /open-url HTTP endpoint accepting attacker-controlled input that can be passed unsanitized to an open() call; under default configurations Metro may bind to external interfaces, making developer systems reachable from the internet. JFrog disclosed the vulnerability in November 2025, and multiple proof-of-concept exploits emerged after public disclosure; affected versions were reported as @react-native-community/cli-server-api 4.8.0 through 20.0.0-alpha.2, with a fix in 20.0.0+.
VulnCheck telemetry and honeypot/canary observations indicate operational exploitation beginning Dec 21, 2025, with repeat activity on Jan 4 and Jan 21, 2026, delivering consistent payloads rather than one-off probing. Observed attacks used Base64-encoded PowerShell delivered in HTTP POST bodies to exposed endpoints; the script added Microsoft Defender exclusions (including the current working directory and C:\Users\<Username>\AppData\Local\Temp), established a raw TCP connection to 8.218.43[.]248:60124, downloaded an additional payload to the temp directory, and executed it. The downloaded binary was described as Rust-based with anti-analysis checks, and exploitation attempts were reported as originating from 5.109.182[.]231, 223.6.249[.]141, and 134.209.69[.]155, underscoring the risk of internet-exposed development infrastructure being used as an initial access vector.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
CISA issued a warning about the React Native Community command injection vulnerability being exploited in attacks, further elevating the issue's visibility for defenders. This marked a U.S. government alert following earlier private-sector reporting of active exploitation.
Multiple security news outlets amplified VulnCheck's findings, describing Metro4Shell as a critical unauthenticated command injection flaw in React Native's Metro server and recommending upgrades to fixed @react-native-community/cli versions and restricting network exposure. Coverage also noted that proof-of-concept exploit code had appeared publicly, increasing exploitation risk.
VulnCheck published research disclosing that CVE-2025-11953, dubbed Metro4Shell, had been exploited in the wild since December 2025. The report detailed the observed payload chain, emphasized the risk from internet-exposed developer tooling, and noted the disconnect between confirmed exploitation and low public recognition.
A further round of attacks was observed in late January, again using cmd.exe to launch a base64-encoded PowerShell loader that added Microsoft Defender exclusions, contacted attacker infrastructure, and downloaded a UPX-packed Rust payload. Related infrastructure also hosted a Linux payload, suggesting multi-OS targeting.
VulnCheck observed additional exploitation activity on a later wave in early January, indicating the activity was sustained and operational rather than one-off scanning or testing. The intrusion chain remained consistent across observed attacks.
VulnCheck's Canary network first observed real-world exploitation of CVE-2025-11953 against internet-exposed React Native Metro Development Server instances. The attacks used the vulnerable /open-url endpoint to achieve unauthenticated command execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceindusface.com
Open sourcescworld.com
Open sourcesocradar.io
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.