React Native is a tool tracked across 7 threat clusters and 13 intelligence report mentions on ThreatCluster. First observed November 5, 2025; most recent activity April 20, 2026.
On March 16, 2026, two React Native npm packages, [email protected] and [email protected], were compromised in a supply chain attack attributed to Glassworm malware. The…
In March 2026, Kaspersky identified over twenty phishing applications in the Apple App Store that impersonate popular cryptocurrency wallets. These malicious apps redirect users to fraudulent web pages that mimic the…
JFrog researchers identified a critical remote code execution vulnerability (CVE-2025-11953) in the React Native CLI, impacting developers using versions 4.8.0 to 20.0.0-alpha.2. Developers are advised to update to the…
Hackers are exploiting the critical vulnerability CVE-2025-11953 in the Metro server for React Native, affecting developers on Windows, Linux, and macOS. The vulnerability allows unauthenticated attackers to execute…
A critical remote code execution (RCE) vulnerability has been identified in the @react-native-community/cli package, affecting millions of developers. The flaw, tracked as CVE-2025-11953, allows unauthenticated…
A critical remote code execution (RCE) vulnerability (CVE-2025-11953) has been identified in the React Native CLI, affecting developers using versions 4.8.0 to 20.0.0-alpha.2. This flaw allows unauthenticated attackers…
Cyble Research and Intelligence Labs have identified a new NFC relay attack campaign named 'RelayNFC' in Brazil. This campaign involves a malicious app distributed through phishing sites that falsely claims to secure…