Skip to content
Glassworm Hits Popular React Native Packages With Credential

Glassworm Hits Popular React Native Packages With Credential

Cybersecuritynews Tushar Subhra Dutta March 17, 2026

A coordinated supply chain attack struck the developer community on March 16, 2026, when a threat actor known as Glassworm backdoored two widely used React Native npm packages, turning them into silent credential and cryptocurrency stealers. The affected packages — [email protected] and [email protected] — were published within minutes of each other by the same publisher, AstrOOnauta, and together accounted […]

Extracted Entities

Attack Types (1)

Malware (1)

Tools (1)