Cybersecurity & Privacy — 2026-03-20

Glassworm Hijacks Popular React Native npm Packages; 134,000+ Monthly Downloads Compromised

The Glassworm threat actor hijacked two popular React Native npm packages -- react-native-international-phone-number (92K monthly downloads) and react-native-country-select (42K) -- across three attack waves between March 16-18. The backdoor installs a multi-stage Windows credential and crypto stealer via a preinstall hook, executing automatically on npm install. Infrastructure overlaps link the campaign to Glassworm's broader supply chain operation that previously compromised 433 repositories.

Analysis
Prior INTSUM covered the broader Glassworm campaign hitting GitHub/npm/VSCode repositories. This represents a targeted escalation against high-traffic React Native packages specifically, increasing the blast radius of the original campaign.

View in full brief →

UNCLASSIFIED // OPEN SOURCE