Skip to content
Artwork for React Native Radio
React Native Radio · June 19 · 36 min

RNR 366 - Securing React Native Apps in the AI Era

Robin and Mazen unpack the rise of AI-powered security threats, from the TanStack breach to compromised React Native packages and GitHub supply chain attacks. Learn practical ways to secure your React Native apps, manage dependencies safely, and reduce risk in modern mobile development. Show Notes Snyk: TanStack Compromised Wiz: Mini Shai-Hulud Strikes Again TanStack: Hardening Followup TanStack: Full Postmortem StepSecurity: Malicious RN Packages Metro4Shell CVE-2025-11953 JFrog: CVE-2025-11953 Deep Dive ReactCon Talk: Aleksandra Desmurs-Linczewska Matteo Collina: Why Trusted Publishing Can't Save Us npm Security Best Practices React Native Security Docs pull_request vs pull_request_target explained Connect With Us! Robin Heinze: @robinheinze Mazen Chami: @mazenchami React Native Radio: @ReactNativeRdio This episode is brought to you by Infinite Red! Infinite Red is a premier mobile app consultancy, especially focused on Expo and React Native, located fully remote in the US. We’re a team of 30 with highly experienced mobile app developers and have been doing this for over a decade. We are also one of the first development teams to adopt agentic coding in a way that keeps high quality standards and aren’t afraid to do things the old school way if we need to. If you’re looking for mobile app or React Native or Expo expertise for your next project, hit us up at infinite.red/radio.

0:00-36:48

transcript

No transcript — this publisher did not publish one.

show notes

Robin and Mazen unpack the rise of AI-powered security threats, from the TanStack breach to compromised React Native packages and GitHub supply chain attacks. Learn practical ways to secure your React Native apps, manage dependencies safely, and reduce risk in modern mobile development.

 

Show Notes

  1. Snyk: TanStack Compromised
  2. Wiz: Mini Shai-Hulud Strikes Again
  3. TanStack: Hardening Followup
  4. TanStack: Full Postmortem
  5. StepSecurity: Malicious RN Packages
  6. Metro4Shell CVE-2025-11953
  7. JFrog: CVE-2025-11953 Deep Dive
  8. ReactCon Talk: Aleksandra Desmurs-Linczewska
  9. Matteo Collina: Why Trusted Publishing Can't Save Us
  10. npm Security Best Practices
  11. React Native Security Docs
  12. pull_request vs pull_request_target explained

 

Connect With Us!

 

This episode is brought to you by Infinite Red!

Infinite Red is a premier mobile app consultancy, especially focused on Expo and React Native, located fully remote in the US. We’re a team of 30 with highly experienced mobile app developers and have been doing this for over a decade. We are also one of the first development teams to adopt agentic coding in a way that keeps high quality standards and aren’t afraid to do things the old school way if we need to. If you’re looking for mobile app or React Native or Expo expertise for your next project, hit us up at infinite.red/radio.

links19