Junglewise Threat Intelligence

CVE-2025-59144: debug npm package supply chain compromise via account takeover

CVE-2025-59144 · Severity: medium · CVSS 4 · Published 2025-09-15

Vendors: npm.

Executive brief

The debug package, a widely-used JavaScript debugging utility, was compromised on npm when its publishing account was taken over via phishing. Version 4.4.2 was released with injected malware designed to intercept cryptocurrency transactions in web browsers, targeting wallets like MetaMask. While server and command-line environments are unaffected, any web applications or browser-bundled code using this version may have active malware embedded in their production bundles. Developers must rebuild all browser bundles, purge cached versions, and upgrade to patched releases to eliminate the threat.

Technical details

This supply-chain compromise stems from a phishing attack that compromised the npm publishing credentials of the debug package maintainer on 8 September 2025. The attacker published version 4.4.2, which is functionally identical to 4.4.1 but with embedded malware injected into src/index.js. The malware payload targets browser environments (checks for typeof window !== 'undefined') and attempts to redirect cryptocurrency transactions to attacker-controlled addresses, specifically targeting MetaMask and other crypto wallets. Node.js, local, and server-side environments are not affected due to the runtime check. npm removed the malicious version from the registry the same day, and the maintainer published patch versions 4.4.3+ on 13 September to cache-bust compromised versions. Users must not only upgrade but also completely rebuild browser bundles from scratch to remove any embedded instances of the malware.

Affected products

  • debug-js debug 4.4.2

Timeline

  • 2025-09-08: other: npm publishing account for debug compromised via phishing attack
  • 2025-09-08: exploited: Malicious version 4.4.2 published to npm with embedded malware
  • 2025-09-08: other: npm removed version 4.4.2 from registry during same day
  • 2025-09-15: disclosed: Public disclosure via GitHub advisory GHSA-4x49-vf9v-38px and CVE-2025-59144
  • 2025-09-13: patched: Patched versions 4.4.3+ published by maintainer

References