CVE-2025-59038

Prebid.js is a free and open source library for publishers to quickly implement header bidding. NPM users of prebid 10.9.2 may have been briefly compromised by a malware campaign. The malicious code attempts to redirect crypto transactions on the site to the attackers' wallet. Version 10.10.0 fixes the issue. As a workaround, it is also possible to downgrade to 10.9.1.
CVSS

No CVSS.

Configurations

No configuration.

History

09 Sep 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-09 23:15

Updated : 2025-09-11 17:14


NVD link : CVE-2025-59038

Mitre link : CVE-2025-59038

CVE.ORG link : CVE-2025-59038


JSON object : View

Products Affected

No product.

CWE
CWE-506

Embedded Malicious Code