Skip to main content
News Directory 3
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Menu
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Gluestack NPM Supply Chain Attack: 960K Downloads Affected - News Directory 3

Gluestack NPM Supply Chain Attack: 960K Downloads Affected

June 7, 2025 Catherine Williams Tech
News Context
At a glance
  • A important supply⁢ chain attack has infiltrated NPM, compromising 16 popular ⁢Gluestack 'react-native-aria' packages.
  • The compromise began June 6, with the initial malicious⁢ version of ‍the react-native-aria/focus package appearing at 4:33 p.m.
  • Aikido Security discovered the⁣ supply chain attack, identifying obfuscated code injected into the lib/index.js file of ⁢multiple packages.
Original source: bleepingcomputer.com


NPM Supply Chain Attack Compromises React Native Aria Packages














Key Points

  • Popular NPM packages hit⁢ by supply‍ chain attack.
  • Malicious code injects remote access trojan (RAT).
  • Compromised ⁣packages have nearly 1 million weekly ‍downloads.

NPM Supply chain Attack‍ Targets React Native Aria Packages

updated June 07, 2025

A important supply⁢ chain attack has infiltrated NPM, compromising 16 popular ⁢Gluestack ‘react-native-aria’ packages. the affected packages, boasting over 950,000 weekly downloads, ⁣now contain malicious code functioning as ‍a remote access trojan (RAT).

The compromise began June 6, with the initial malicious⁢ version of ‍the react-native-aria/focus package appearing at 4:33 p.m. EST. Since then, threat actors have released new, compromised ‍versions of 16 out of 20 Gluestack react-native-aria packages, some as recently as two hours before the report.

Screenshot showing ongoing compromise of NPM packages
Ongoing⁣ compromise of⁢ NPM packages

Aikido Security discovered the⁣ supply chain attack, identifying obfuscated code injected into the lib/index.js file of ⁢multiple packages. The react-native-aria ‍packages ⁢are popular JavaScript libraries used for building accessible user interfaces.

The compromised react-native-aria packages include button, checkbox, combobox, disclosure, focus, interactions, listbox, menu,‍ overlays, radio, switch, toggle, utils, separator and slider. The gluestack-ui/utils package was ⁤also affected. These packages collectively see approximately 960,000⁢ weekly downloads,amplifying the ⁤potential impact of this supply chain attack.

The malicious code,heavily obfuscated,is appended to the end of the index.js file, padded with spaces to evade ⁣easy detection⁢ within the NPM code viewer. Aikido⁣ Security noted the injected code closely resembles‍ a remote access trojan ⁢found in a previous NPM compromise from last month.

Malicious code added to end of index.js file
Malicious code added to end of index.js file

Analysis indicates the ⁤RAT connects to a command ‍and ⁣control server, awaiting instructions. These⁤ commands enable attackers to change directories, upload files, and execute shell commands on compromised systems. ⁣The trojan also manipulates the Windows PATH habitat variable,perhaps hijacking legitimate Python commands for malicious purposes.

Aikido security researcher Charlie Eriksen attempted to alert Gluestack to ⁢the compromise via GitHub issues, but has not yet received a response. Eriksen ‍stated that ⁣NPM has been ‍contacted and each package reported,but the ‍resolution process typically takes several days.

Aikido believes the same threat actors are behind this attack and the‍ compromise of four other NPM packages earlier in ‍the week: biatec-avm-gas-station, cputil-node, lfwfinance/sdk, and lfwfinance/sdk-dev. BleepingComputer has reached out to Gluestack for comment but has not‍ yet received a reply.

What’s next

Users ⁢of the affected react-native-aria packages⁣ should ‍instantly check their projects for the compromised versions and update to safe releases once available. Further examination into the ‍scope and impact ⁤of the attack is ongoing.

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

Worth a look

  • Exoskeletons Evolve With Adaptive Algorithms and Soft Materials
  • TMOG monitors system performance on Windows, macOS and Linux

Related

Search:

News Directory 3

News Directory 3 catalogs US newspapers, news services, newsstands and digital news outlets across all 50 states. Browse local publishers by city, state, or topic, and follow current headlines linked back to their original sources.

Quick Links

  • Disclaimer
  • Terms and Conditions
  • About Us
  • Advertising Policy
  • Contact Us
  • Cookie Policy
  • Editorial Guidelines
  • Privacy Policy

Browse by State

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado

© 2026 News Directory 3. All rights reserved.
For contact, advertising, copyright, issues email: office@newsdirectory3.com