Glassworm Malware Targets React Native npm Packages in Supply Chain Attack
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On March 16, 2026, two React Native npm packages, [email protected] and [email protected], were compromised in a supply chain attack attributed to Glassworm malware. The malicious versions included an install-time loader that executes a multi-stage Windows credential and crypto stealer during a routine npm install. The attack affected a significant number of developers, with the compromised packages reporting a combined total of 29,763 downloads in the last week. The malware's install script includes obfuscation and checks for Russian language and timezone signals, indicating a targeted approach. The attack highlights the risks associated with third-party package dependencies in software development. The original versions of the packages do not contain the malicious code, suggesting a specific compromise of the publisher's releases. The situation is ongoing as security professionals assess the impact and potential remediation strategies.
Key Points: • Two popular React Native npm packages were backdoored with malware on March 16, 2026. • The malicious code executes during a routine npm install, affecting thousands of developers. • The malware includes geographic filters, indicating a targeted approach likely linked to Russian threat actors.