Executive brief
The is-arrayish npm package, a widely-used JavaScript utility library, was compromised after its npm account was taken over via phishing. Version 0.3.3 contains malware designed to intercept and redirect cryptocurrency transactions to the attacker's accounts when the library is used in web browsers. While the malware was removed from npm's public registry, developers using the package in browser-based applications (such as web frontends bundled with tools like Webpack or Vite) could have the malicious code compiled into their applications and need to rebuild their projects.
Technical details
This is a supply-chain attack involving embedded malicious code (CWE-506) inserted into version 0.3.3 of the is-arrayish npm package after the publisher's account was compromised via phishing. The malware payload is designed to operate only in browser environments and targets cryptocurrency transactions by attempting to redirect wallet interactions (notably MetaMask) to attacker-controlled addresses. Attack vector is network-based; any browser application that bundled version 0.3.3 (whether via direct script inclusion or build tools like Webpack, Rollup, Vite, or Next.js) may have the malware compiled into its deliverable. The vulnerability does not affect server-side or command-line usage. npm removed the package from its public registry on 8 September 2025; a patched version 0.3.4 was released on 13 September 2025. Affected users must update, clear local caches, and rebuild browser bundles from source.
Affected products
- npm is-arrayish 0.3.3
Timeline
- 2025-09-08: exploited: npm account compromised via phishing; malicious version 0.3.3 published
- 2025-09-13: patched: Patched version 0.3.4 released
- 2025-09-15: disclosed: Advisory GHSA-frh7-2f84-v9mw and CVE-2025-59331 published