Hackers Exploit CVE-2025-11953 Vulnerability in React Native CLI Package
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The vulnerability CVE-2025-11953, also known as Metro4Shell, affects the Metro Development Server in the ‘@react-native-community/cli’ npm package. VulnCheck first observed exploitation of this flaw on December 21, 2025, following its documentation by JFrog in November 2025. With a CVSS score of 9.8, this vulnerability allows remote unauthenticated attackers to execute arbitrary operating system commands on the host system.
In a recent attack detected by VulnCheck, threat actors utilized this flaw to deliver a Base64-encoded PowerShell script. This script performs various actions, including creating exclusions for Microsoft Defender Antivirus in the current working directory and the temporary folder. It also establishes a raw TCP connection to an attacker-controlled host and port, enabling the retrieval and execution of malicious binaries.
The attacks have been traced back to specific IP addresses, including 5.109.182.231, 223.6.249.141, and 134.209.69.155. VulnCheck noted that the payloads delivered during these attacks have shown consistency over multiple weeks, indicating that this is an operational use rather than mere vulnerability probing.
Implications for Users and Organizations
This incident highlights a critical pattern in cybersecurity: development infrastructure can quickly become production infrastructure once it is accessible. Organizations using the ‘@react-native-community/cli’ package should be aware of the risks associated with this vulnerability and take immediate action to mitigate potential threats.
Users and organizations should monitor their systems for any unusual activity, especially if they are utilizing the affected npm package. Regularly updating software and applying security patches is essential to protect against such vulnerabilities.
Additionally, implementing robust security measures, such as network segmentation and strict access controls, can help minimize the impact of similar attacks in the future. Organizations should also consider conducting regular security audits to identify and address potential vulnerabilities proactively.
- CVE-2025-11953: A critical vulnerability allowing remote command execution on affected systems.
- Metro Development Server: The component of the ‘@react-native-community/cli’ npm package that is exploited in this attack.
- PowerShell script: A malicious script used to modify antivirus settings and establish connections to attacker-controlled hosts.
- VulnCheck: The cybersecurity company that reported the exploitation of this vulnerability.
- JFrog: The organization that first documented the vulnerability in November 2025.
Key Takeaways
- Update the ‘@react-native-community/cli’ npm package to the latest version to mitigate vulnerabilities.
- Monitor systems for unusual activity, especially if using the Metro Development Server.
- Implement strict access controls and network segmentation to limit exposure to potential attacks.
- Regularly review and update antivirus settings to ensure they are not being modified by malicious scripts.
- Conduct periodic security audits to identify and address vulnerabilities in your development infrastructure.
Key Terms & Concepts
- CVE-2025-11953: In this article, CVE-2025-11953 refers to a critical vulnerability that allows remote command execution on affected systems.
- Metro Development Server: Metro Development Server is a component of the ‘@react-native-community/cli’ npm package that has been exploited by attackers.
- PowerShell script: A PowerShell script is a type of script used to automate tasks, which in this case is used maliciously to modify antivirus settings.
- VulnCheck: VulnCheck is a cybersecurity company that reported the exploitation of the CVE-2025-11953 vulnerability.
- JFrog: JFrog is the organization that first documented the CVE-2025-11953 vulnerability in November 2025.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.