The gluestack and react-native-aria Supply Chain Attack
Updated 5 Oct 2026 · Incident date 6 Jun 2025 · npm
@react-native-aria/* and @gluestack-ui/* - 17 packages, ~1M weekly downloads, poisoned patch releaseslib/index.jsIn June 2025 an attacker published poisoned patch releases of 16 @react-native-aria packages and one @gluestack-ui package on npm. The packages had more than one million weekly downloads combined.
The injected code is a remote access trojan. It lets an outsider run commands on the developer's computer. This page lists the facts from the gluestack incident report, Aikido Security and BleepingComputer.
What happened
An attacker used a leaked npm access token that belonged to a maintainer and had no two-factor protection. The attacker published malicious versions of existing packages. The gluestack incident report describes this cause.
The timeline from that report, in GMT:
- 6 June 2025, 21:33: the first package, @react-native-aria/focus, is compromised after about eight months without a release.
- 7 June 2025, 00:37 to 00:48: eight more packages are compromised.
- 7 June 2025, 14:28 to 14:46: a second wave hits seven more packages.
- 8 June 2025: Aikido Security identifies the compromise and gluestack starts containment.
- 9 June 2025: gluestack publishes its disclosure.
The poisoned releases were available for about 17 hours. Aikido reports that the code is on the last line of lib/index.js and uses long runs of spaces to hide in the npm web viewer. The packages are front-end UI components. They had no network code before the attack.
The trojan connects to a command server. It runs shell commands and uploads files or whole directories. On Windows it adds a fake Python folder to the PATH variable. This lets it replace the python and pip commands. Aikido notes that the code is almost the same as malware in earlier npm compromises of other packages.
Affected versions
The sources list these malicious versions. Packages are in the @react-native-aria scope unless noted.
- focus 0.2.10
- utils 0.2.13
- overlays 0.3.16
- interactions 0.2.17
- toggle 0.2.12
- switch 0.2.5
- checkbox 0.2.11
- radio 0.2.14
- button 0.2.11
- menu 0.2.16
- listbox 0.2.10
- tabs 0.2.14
- disclosure 0.2.9
- slider 0.2.13
- separator 0.2.7
- combobox 0.2.8 per gluestack, 0.2.10 per BleepingComputer
- One @gluestack-ui package at 0.1.16 and 0.1.17. Gluestack names it @gluestack-ui/core. Aikido and BleepingComputer name it @gluestack-ui/utils.
Treat both gluestack package names as suspect and check the gluestack report for the final list. Gluestack deprecated the bad versions on npm. It did not unpublish them because other packages depend on them.
Indicators of compromise
- Command servers:
136.0.9.8and85.239.62.36, both on ports 3306 and 27017. - Windows persistence path:
%LOCALAPPDATA%\Programs\Python\Python3127 - Backdoor command names in the code:
ss_info,ss_ip,ss_upf,ss_upd,ss_fcd. - A lookup to
http://ip-api.com/jsonfor the public IP. - Very long space padding on the last line of
lib/index.jsin an affected package.
How to check
List every affected package in your dependency tree and compare the versions with the list above.
npm ls --all | grep -E "@react-native-aria|@gluestack-ui"
Then search installed code and your logs for the indicators.
grep -rlE "136\.0\.9\.8|85\.239\.62\.36|ss_info" node_modules/@react-native-aria node_modules/@gluestack-ui
On Windows, check whether the Python3127 folder exists under your local Programs\Python directory. Review firewall logs for connections to the two IP addresses.
What to do now
- Find any affected version in your lockfile and install a clean release from before the attack.
- Delete node_modules and reinstall from the corrected lockfile.
- If a bad version ran on a machine, treat the machine as untrusted. The sources suggest a full rebuild if compromise is confirmed.
- Rotate secrets and tokens that were present on that machine.
- Block the two command server IP addresses and review past traffic to them.
- Turn on two-factor authentication for every npm publisher account.
Vigilance compares the version you trust with a new one. Here, lib/index.js in UI packages with no network code gained a persistent command connection and arbitrary command execution. That is a new capability in an existing file.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 45 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED lib/index.js It now downloads from the internet, runs other programs and restarts itself after a reboot. It did not before.
Frequently asked questions
Which gluestack and react-native-aria versions were compromised?
Sixteen @react-native-aria packages and one @gluestack-ui package were affected, for example @react-native-aria/focus 0.2.10 and utils 0.2.13. The page lists each version from the gluestack, Aikido and BleepingComputer reports.
How did the attacker get into the gluestack packages?
Gluestack says the attacker used a leaked npm access token that belonged to a maintainer. The token had no two-factor protection.
What does the gluestack malware do?
It is a remote access trojan. It runs shell commands, uploads files and directories to the attacker and collects system details. On Windows it adds a fake Python folder to PATH.
Sources
More supply chain attacks
- @apexacc/cli Defender-blinding C2 loader 17 Sept 2026
- keyv / cacheable npm worm (Shai-Hulud third wave) 4 Aug 2026
- Mastra AI npm compromise (Sapphire Sleet) 17 Jun 2026
- TanStack npm compromise (Mini Shai-Hulud) 11 May 2026
All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.