Junglewise Threat Intelligence

CVE-2025-59038: Prebid.js malicious code injection in NPM package

CVE-2025-59038 · Severity: medium · CVSS 4 · Published 2025-09-11

Vendors: npm.

Executive brief

Prebid.js is a popular open-source library for web-based digital advertising auctions. Version 10.9.2 of the NPM package was compromised and contained malicious code designed to redirect cryptocurrency transactions from affected websites to an attacker-controlled wallet. This affects any website using the compromised version, potentially resulting in loss of customer funds.

Technical details

A supply-chain attack compromised the Prebid.js NPM package at version 10.9.2, injecting malicious JavaScript code (CWE-506: Embedded Malicious Code). The attack modifies transaction handling logic to intercept and redirect cryptocurrency transfers. The vulnerability requires user interaction (site visitor with an affected application) and no authentication, making it exploitable to any user of a website running the compromised package version. Exploitation results in crypto wallet redirection and financial loss. The malicious code was removed in version 10.10.0.

Affected products

  • Prebid Prebid.js 10.9.2

Timeline

  • 2025-09-09: disclosed: Initial discovery and disclosure
  • 2025-09-11: patched: Version 10.10.0 released with fix

References