Cybercriminals are exploiting a critical vulnerability affecting the Metro Development Server in the popular npm package “@react-native-community/cli“. Cybersecurity firm VulnCheck reported that it first observed the exploit, CVE-2025-11953 (also known as Metro4Shell), on December 21, 2025. With a CVSS score of 9.8, the vulnerability allows remote, unauthenticated attackers to execute arbitrary operating system commands on the underlying host.
See also: Google Play: Malicious app with 50,000 downloads distributed by Anatsa malware

Details of the vulnerability were first documented by JFrog in November 2025.
Despite the fact that more than a month has passed since the initial exploitation, the activity has yet to receive widespread public recognition.
Metro4Shell Vulnerability: How Attacks Work
In the attack detected on the company's honeypot network, threat actors had used the Metro4Shell vulnerability to deliver a Base64-encoded PowerShell script, which is configured to perform a series of actions, including Microsoft Defender Antivirus exclusions for the current working directory and the temporary folder (“C:\Users\
See also: AI strengthens the attack chain in AWS environments
The PowerShell script also creates a raw TCP connection to a host and port controlled by the attacker (“8.218.43[.]248:60124”) and sends a request to retrieve data, write it to a file in the temporary directory , and execute it. The downloaded binary is based on Rust and has anti-parsing checks to prevent static inspection.

Researchers have identified several IP addresses from which the attacks originate:
- 5.109.182[.]231
- 223.6.249[.]141
- 134.209.69[.]155
See also: Vulnerability in Apache Syncope allows user session hijacking
Describing the activity as neither experimental nor exploratory, VulnCheck said the delivered payloads were consistent over several weeks of exploitation, indicating operational use rather than vulnerability investigation or proof-of-concept testing.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
