Skip to content
Hackers Exploiting React Native’s Metro Server in the Wild to Attack Developers

Hackers Exploiting React Native’s Metro Server in the Wild to Attack Developers

Cybersecuritynews Guru Baran February 3, 2026

Threat actors are actively exploiting a critical remote code execution vulnerability in React Native’s Metro Development Server to deliver advanced malware payloads across Windows and Linux systems. VulnCheck’s Canary honeypot network first detected operational exploitation of CVE-2025-11953 dubbed “Metro4Shell” on December 21, 2025, with continued attacks observed in January 2026, yet the vulnerability remains largely […]

Extracted Entities

APT Groups (1)

Attack Types (1)

Platforms (2)