Junglewise Threat Intelligence

CVE-2025-59037: DuckDB NPM packages malware compromise

CVE-2025-59037 · Severity: medium · CVSS 4 · Published 2025-09-09

Vendors: npm.

Executive brief

DuckDB's Node.js packages on npm were compromised with malicious code designed to interfere with cryptocurrency transactions. Four packages and specific versions (duckdb 1.3.3, @duckdb/node-api 1.3.3, @duckdb/node-bindings 1.3.3, and @duckdb/duckdb-wasm 1.29.2) were affected before being removed by npm within hours. Any developer who installed these versions could have their applications executing malicious code that targets cryptocurrency operations.

Technical details

A supply-chain attack via compromised npm package credentials resulted in malicious versions of four DuckDB npm packages being published. The attacker used a phishing attack against a DuckDB maintainer to steal npm credentials (username, password, and bypass 2FA by resetting it on a lookalike website npmjs.help), then leveraged those credentials to publish packages containing cryptocurrency-targeting malware. The malicious code was embedded directly in the published package versions. An attacker can achieve arbitrary code execution on any developer's machine and build systems that install the compromised versions. The affected versions were removed from npm within 4 hours of discovery, and patched versions (duckdb 1.3.4, @duckdb/node-api 1.3.4-alpha.27, @duckdb/node-bindings 1.3.4-alpha.27, @duckdb/duckdb-wasm 1.30.0) were released.

Affected products

  • DuckDB duckdb 1.3.3
  • DuckDB node-api 1.3.3
  • DuckDB node-bindings 1.3.3
  • DuckDB duckdb-wasm 1.29.2

Timeline

  • 2025-09-09: disclosed: Security advisory published
  • 2025-09-08: exploited: Phishing attack against maintainer occurred; malicious packages published
  • 2025-09-09: patched: Patched versions released (1.3.4, 1.3.4-alpha.27, 1.30.0)

References