Prebid.js NPM package briefly compromised
Description
Published by the National Vulnerability Database
Sep 9, 2025
Published to the GitHub Advisory Database
Sep 11, 2025
Reviewed
Sep 11, 2025
Last updated
Sep 11, 2025
Impact
NPM users of prebid 10.9.2. The malicious code attempts to redirect crypto transactions on the site to the attackers' wallet.
Patches
10.10.0 is solved
References
https://www.sonatype.com/blog/npm-chalk-and-debug-packages-hit-in-software-supply-chain-attack
References