Junglewise Threat Intelligence

CVE-2025-59330: error-ex npm package malware from account takeover

CVE-2025-59330 · Severity: medium · CVSS 4 · Published 2025-09-15

Vendors: npm.

Executive brief

The error-ex npm package, a JavaScript utility library used in web applications and build tools, was compromised after its npm publishing account was taken over via phishing. Version 1.3.3 contains malware designed to intercept and redirect cryptocurrency transactions from browser-based wallets. Applications bundled with this version that run in browsers are at risk of crypto theft; server-side and command-line uses are unaffected.

Technical details

The vulnerability involves embedded malicious code (CWE-506) injected into npm package version 1.3.3 following an account takeover via phishing attack on 8 September 2025. The malware payload targets browser environments specifically, attempting to hijack cryptocurrency transactions and redirect funds to attacker-controlled wallets, particularly focusing on MetaMask and similar browser-based cryptocurrency wallets. Attack vector is network-based with no authentication required, though exploitation requires the malicious package to be bundled into a browser-based application. Server-side, CLI, and local application contexts are not affected. The package was removed from the npm registry on 8 September 2025, and patched version 1.3.4 was released on 13 September 2025. Users must update, clear caches, and rebuild browser bundles to ensure the malicious code is not present.

Affected products

  • npm error-ex 1.3.3

Timeline

  • 2025-09-08: other: npm account takeover via phishing; malicious version 1.3.3 published
  • 2025-09-15: disclosed: Vulnerability disclosed as GHSA-6jp5-hh4c-8c5h and CVE-2025-59330
  • 2025-09-13: patched: Patched version 1.3.4 released

References