Gluestack NPM Supply Chain Attack: 960K Downloads Affected
- A important supply chain attack has infiltrated NPM, compromising 16 popular Gluestack 'react-native-aria' packages.
- The compromise began June 6, with the initial malicious version of the react-native-aria/focus package appearing at 4:33 p.m.
- Aikido Security discovered the supply chain attack, identifying obfuscated code injected into the lib/index.js file of multiple packages.
NPM Supply chain Attack Targets React Native Aria Packages
updated June 07, 2025
A important supply chain attack has infiltrated NPM, compromising 16 popular Gluestack ‘react-native-aria’ packages. the affected packages, boasting over 950,000 weekly downloads, now contain malicious code functioning as a remote access trojan (RAT).
The compromise began June 6, with the initial malicious version of the react-native-aria/focus package appearing at 4:33 p.m. EST. Since then, threat actors have released new, compromised versions of 16 out of 20 Gluestack react-native-aria packages, some as recently as two hours before the report.

Aikido Security discovered the supply chain attack, identifying obfuscated code injected into the lib/index.js file of multiple packages. The react-native-aria packages are popular JavaScript libraries used for building accessible user interfaces.
The compromised react-native-aria packages include button, checkbox, combobox, disclosure, focus, interactions, listbox, menu, overlays, radio, switch, toggle, utils, separator and slider. The gluestack-ui/utils package was also affected. These packages collectively see approximately 960,000 weekly downloads,amplifying the potential impact of this supply chain attack.
The malicious code,heavily obfuscated,is appended to the end of the index.js file, padded with spaces to evade easy detection within the NPM code viewer. Aikido Security noted the injected code closely resembles a remote access trojan found in a previous NPM compromise from last month.

Analysis indicates the RAT connects to a command and control server, awaiting instructions. These commands enable attackers to change directories, upload files, and execute shell commands on compromised systems. The trojan also manipulates the Windows PATH habitat variable,perhaps hijacking legitimate Python commands for malicious purposes.
Aikido security researcher Charlie Eriksen attempted to alert Gluestack to the compromise via GitHub issues, but has not yet received a response. Eriksen stated that NPM has been contacted and each package reported,but the resolution process typically takes several days.
Aikido believes the same threat actors are behind this attack and the compromise of four other NPM packages earlier in the week: biatec-avm-gas-station, cputil-node, lfwfinance/sdk, and lfwfinance/sdk-dev. BleepingComputer has reached out to Gluestack for comment but has not yet received a reply.
What’s next
Users of the affected react-native-aria packages should instantly check their projects for the compromised versions and update to safe releases once available. Further examination into the scope and impact of the attack is ongoing.
