Glassworm Malware Targets React Native npm Packages in Supply Chain Attack

Glassworm Malware Targets React Native npm Packages in Supply Chain Attack

First seen 17 Mar 2026, 13:07 UTC Aikido.DevGbhackersCybersecuritynews 89% similarity 75.0

Article Content

Browse articles
ThreatCluster

On March 16, 2026, two React Native npm packages, [email protected] and [email protected], were compromised in a supply chain attack attributed to Glassworm malware. The malicious versions included an install-time loader that executes a multi-stage Windows credential and crypto stealer during a routine npm install. The attack affected a significant number of developers, with the compromised packages reporting a combined total of 29,763 downloads in the last week. The malware's install script includes obfuscation and checks for Russian language and timezone signals, indicating a targeted approach. The attack highlights the risks associated with third-party package dependencies in software development. The original versions of the packages do not contain the malicious code, suggesting a specific compromise of the publisher's releases. The situation is ongoing as security professionals assess the impact and potential remediation strategies.

Key Points: • Two popular React Native npm packages were backdoored with malware on March 16, 2026. • The malicious code executes during a routine npm install, affecting thousands of developers. • The malware includes geographic filters, indicating a targeted approach likely linked to Russian threat actors.

ThreatCluster AI

Timeline

2026-03-16
Malicious versions of npm packages published with backdoored code.
2026-03-16
Packages reported a combined total of 29,763 downloads.

Community

Browse all →