Product
React Native CLI
- First Reported
- May 21, 2026
- Latest Reported
- May 21, 2026
Reported Context (1)
- Cloud Storage impersonation phishing campaign.Active exploitation of CVE-2025-11953 (Metro4Shell) in React Native CLI was observed with source IP 5.109.182[.]231 on Saudi Arabia's Mobily network (AS35819), delivering Hunt.io Report Maps 1,357 C2 Servers Across 98 Middle Eastern Providers
CVE (1)
Malware (17)
Threat Actors (8)
MITRE ATT&CK (9)
Vendors (21)
Products (7)
Tools (8)
Industries (5)
Countries (16)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.