{"id":"CVE-2025-59038","aliases":["MAL-2025-46990"],"url":"https://o3.security/vulnerability/CVE-2025-59038","summary":"Prebid.js NPM package briefly compromised","details":"### Impact\nNPM users of prebid 10.9.2. The malicious code attempts to redirect crypto transactions on the site to the attackers' wallet.\n\n### Patches\n10.10.0 is solved\n\n### References\nhttps://www.sonatype.com/blog/npm-chalk-and-debug-packages-hit-in-software-supply-chain-attack","published":"2025-09-11T14:22:40Z","modified":"2025-09-12T01:42:18.787013Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"prebid.js","fixedVersion":"10.10.0"}],"fix":{"url":"https://github.com/prebid/Prebid.js/commit/72c7f184028f51ba15cdac744d56590b0f2b1f1e","label":"prebid/Prebid.js@72c7f18"},"references":[{"type":"WEB","url":"https://github.com/prebid/Prebid.js/security/advisories/GHSA-jwq7-6j4r-2f92"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59038"},{"type":"WEB","url":"https://github.com/prebid/Prebid.js/commit/72c7f184028f51ba15cdac744d56590b0f2b1f1e"},{"type":"PACKAGE","url":"https://github.com/prebid/Prebid.js"},{"type":"WEB","url":"https://github.com/prebid/Prebid.js/releases/tag/10.10.0"},{"type":"WEB","url":"https://www.sonatype.com/blog/npm-chalk-and-debug-packages-hit-in-software-supply-chain-attack"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-09-12T01:42:18.787013Z"}}