Junglewise Threat Intelligence

CVE-2025-59141: simple-swizzle malware in NPM package after account takeover

CVE-2025-59141 · Severity: medium · CVSS 4 · Published 2025-09-15

Vendors: npm.

Executive brief

The simple-swizzle library is a utility package used by web applications and Node.js projects. An attacker compromised the NPM account through phishing and injected malware into version 0.2.3 that attempts to steal cryptocurrency by redirecting transactions from browser-based wallets like MetaMask. Any web applications using this version will execute the malicious code in users' browsers, putting customer cryptocurrency and transaction data at risk.

Technical details

The vulnerability is malicious code (CWE-506) introduced by a compromised NPM publishing account. On 8 September 2025, an attacker gained control via phishing and published version 0.2.3 containing embedded cryptocurrency theft malware. The payload targets browser environments specifically, attempting to intercept and redirect blockchain transactions. The attack requires the package to be installed and bundled/executed in a browser context (via script inclusion, Babel, Rollup, Vite, Next.js, etc.); server-side and CLI applications are not affected. NPM removed the package from its registry the same day; the publisher issued patched versions on 13 September. Users must update to 0.2.4+, clear node_modules and caches, and rebuild browser bundles from scratch.

Affected products

  • npm simple-swizzle 0.2.3

Timeline

  • 2025-09-08: other: NPM account compromised via phishing; malware-laden version 0.2.3 published
  • 2025-09-08: other: NPM removed offending package from registry
  • 2025-09-15: disclosed: Security advisory GHSA-9g9j-rggx-7fmg published
  • 2025-09-13: patched: Patched version 0.2.4 released by package owner

References