Executive brief
Prebid-universal-creative, a JavaScript library used to render advertisements, was compromised in version 1.17.3 on npm and the popular jsdelivr CDN. The malicious version contained crypto-mining malware that could execute arbitrary code on any website embedding this library. This affected websites using the latest or 1.17.3 version, potentially compromising their end-users with malware.
Technical details
The vulnerability is a supply chain attack (CWE-506: Embedded Malicious Code). The npm package prebid-universal-creative version 1.17.3 was compromised with crypto-related malware, likely through account takeover or dependency manipulation. The malicious code would execute in the browser context of any web page using the affected library versions, with no authentication or special preconditions required beyond the victim visiting a site using the compromised package. An attacker could thus achieve arbitrary code execution in browser contexts and perform actions like cryptocurrency mining or stealing session data. The malicious version has been unpublished from npm; users should downgrade to 1.17.2 or earlier and migrate away from pointing to the dynamic "latest" version.
Affected products
- Prebid prebid-universal-creative 1.17.3
Timeline
- 2025-09-11: disclosed: Publicly disclosed on GitHub and OSV
- 2025-09-09: other: Advisory published (predates GitHub disclosure)
- 2025-09-11: patched: Malicious version 1.17.3 unpublished from npm