All vulnerabilities
CRITICALSupply chainexploited in the wild

NPM-GLUESTACK-REACT-NATIVE-ARIA-2025

npm · @react-native-aria/*, @gluestack-ui/* (16+ packages)

Summary

Starting June 6, 2025, a threat actor used a leaked npm access token belonging to a maintainer without 2FA to publish malicious versions of 16-17 React Native Aria and gluestack-ui packages with over 1 million combined weekly downloads. The packages were backdoored with obfuscated Remote Access Trojan (RAT) code hidden using whitespace obfuscation, establishing command-and-control infrastructure and persistence on compromised systems. The same payload was tied to a broader campaign also hitting PyPI; end-user impact was limited by the frontend nature of the libraries and a response within 48 hours.

References

Related vulnerabilities

All Supply chain →