1 of 1
Story summary
- Hackers exploit a critical flaw in the React Native CLI, CVE-2025-11953, to deploy Rust malware.
- The vulnerability allows unauthenticated attackers to execute arbitrary commands on affected systems.
- VulnCheck first detected exploitation on December 21, 2025, though the issue has not received widespread public acknowledgment.
- Attacks use a Base64-encoded PowerShell script that disables Microsoft Defender and connects to an attacker-controlled host, with anti-analysis checks.
