Active attacks exploit Metro4Shell (CVE-2025-11953) in React Native CLI to execute commands and deploy Rust malware.
Strip the types and hotwire the HTML—and triple check your package security while you are at it. JavaScript in 2026 is just ...