The gluestack and react-native-aria Supply Chain Attack

Updated 5 Oct 2026 · Incident date 6 Jun 2025 · npm

Package@react-native-aria/* and @gluestack-ui/* - 17 packages, ~1M weekly downloads, poisoned patch releases
Filelib/index.js

In June 2025 an attacker published poisoned patch releases of 16 @react-native-aria packages and one @gluestack-ui package on npm. The packages had more than one million weekly downloads combined.

The injected code is a remote access trojan. It lets an outsider run commands on the developer's computer. This page lists the facts from the gluestack incident report, Aikido Security and BleepingComputer.

What happened

An attacker used a leaked npm access token that belonged to a maintainer and had no two-factor protection. The attacker published malicious versions of existing packages. The gluestack incident report describes this cause.

The timeline from that report, in GMT:

The poisoned releases were available for about 17 hours. Aikido reports that the code is on the last line of lib/index.js and uses long runs of spaces to hide in the npm web viewer. The packages are front-end UI components. They had no network code before the attack.

The trojan connects to a command server. It runs shell commands and uploads files or whole directories. On Windows it adds a fake Python folder to the PATH variable. This lets it replace the python and pip commands. Aikido notes that the code is almost the same as malware in earlier npm compromises of other packages.

Affected versions

The sources list these malicious versions. Packages are in the @react-native-aria scope unless noted.

Treat both gluestack package names as suspect and check the gluestack report for the final list. Gluestack deprecated the bad versions on npm. It did not unpublish them because other packages depend on them.

Indicators of compromise

How to check

List every affected package in your dependency tree and compare the versions with the list above.

npm ls --all | grep -E "@react-native-aria|@gluestack-ui"

Then search installed code and your logs for the indicators.

grep -rlE "136\.0\.9\.8|85\.239\.62\.36|ss_info" node_modules/@react-native-aria node_modules/@gluestack-ui

On Windows, check whether the Python3127 folder exists under your local Programs\Python directory. Review firewall logs for connections to the two IP addresses.

What to do now

  1. Find any affected version in your lockfile and install a clean release from before the attack.
  2. Delete node_modules and reinstall from the corrected lockfile.
  3. If a bad version ran on a machine, treat the machine as untrusted. The sources suggest a full rebuild if compromise is confirmed.
  4. Rotate secrets and tokens that were present on that machine.
  5. Block the two command server IP addresses and review past traffic to them.
  6. Turn on two-factor authentication for every npm publisher account.

Vigilance compares the version you trust with a new one. Here, lib/index.js in UI packages with no network code gained a persistent command connection and arbitrary command execution. That is a new capability in an existing file.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old @react-native-aria/-prev --new @react-native-aria/-current
files scanned: 45

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    lib/index.js
           It now downloads from the internet, runs other programs and restarts itself after a reboot. It did not before.

Frequently asked questions

Which gluestack and react-native-aria versions were compromised?

Sixteen @react-native-aria packages and one @gluestack-ui package were affected, for example @react-native-aria/focus 0.2.10 and utils 0.2.13. The page lists each version from the gluestack, Aikido and BleepingComputer reports.

How did the attacker get into the gluestack packages?

Gluestack says the attacker used a leaked npm access token that belonged to a maintainer. The token had no two-factor protection.

What does the gluestack malware do?

It is a remote access trojan. It runs shell commands, uploads files and directories to the attacker and collects system details. On Windows it adds a fake Python folder to PATH.

Sources

  1. gluestack.io/blogs/public-incident-report
  2. aikido.dev/blog/supply-chain-attack-on-react-native-aria-ecosystem
  3. bleepingcomputer.com/news/security/supply-chain-attack-hits-gluestack-npm-packages-with-960k-weekly-downloads/

More supply chain attacks

All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free