Hackers are targeting developers by exploiting the critical vulnerability CVE-2025-11953 in the Metro server for React Native to deliver malicious payloads for Windows and Linux.
A compromised Open VSX publisher account was used to distribute malicious extensions in a new GlassWorm supply chain attack.