Skip to content

Prebid.js NPM package briefly compromised in v10.9.2

High
patmmccann published GHSA-jwq7-6j4r-2f92 Sep 9, 2025

Package

npm prebid.js (npm)

Affected versions

10.9.2

Patched versions

10.10.0

Description

Impact

NPM users of prebid 10.9.2. The malicious code attempts to redirect crypto transactions on the site to the attackers' wallet.

Patches

10.10.0 is solved

References

https://www.sonatype.com/blog/npm-chalk-and-debug-packages-hit-in-software-supply-chain-attack

Severity

High

CVE ID

CVE-2025-59038

Weaknesses

No CWEs