Cybersecurity & Privacy — 2026-03-23

npm Supply Chain Attack Hijacks React Native Package Affecting Thousands of Developers

The npm account behind react-native-international-phone-number and react-native-country-select was hijacked between March 16-18, with the attacker changing the account email to a Proton Mail address to lock out the legitimate maintainer. The compromised packages are widely used in React Native mobile applications. The incident reflects the persistent vulnerability of open-source software supply chains to account takeover attacks targeting individual maintainers.

1 sources
  1. Top data breaches of March 2026 (so far) - SharkStriker

View in full brief →

UNCLASSIFIED // OPEN SOURCE