Metro is a technology platform tracked across 3 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed November 6, 2025; most recent activity May 26, 2026.
Metro is the JavaScript bundler and development server used with React Native to build cross‑platform mobile apps. The recent article highlights a critical remote code execution flaw in the React Native CLI that uses Metro, which could allow attackers to compromise developers’ environments and potentially affect related workflows and supply chains.
In March 2026, Iranian hackers linked to the Ministry of Intelligence and Security (MOIS) breached the Los Angeles County Metropolitan Transportation Authority (LACMTA), stealing at least 700 gigabytes of sensitive…
A critical remote code execution (RCE) vulnerability has been identified in the @react-native-community/cli package, affecting millions of developers. The flaw, tracked as CVE-2025-11953, allows unauthenticated…
A critical remote code execution (RCE) vulnerability (CVE-2025-11953) has been identified in the React Native CLI, affecting developers using versions 4.8.0 to 20.0.0-alpha.2. This flaw allows unauthenticated attackers…