Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27596 | Prebid.js NPM package briefly compromised |
Github GHSA |
GHSA-jwq7-6j4r-2f92 | Prebid.js NPM package briefly compromised |
Wed, 10 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Sep 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Prebid.js is a free and open source library for publishers to quickly implement header bidding. NPM users of prebid 10.9.2 may have been briefly compromised by a malware campaign. The malicious code attempts to redirect crypto transactions on the site to the attackers' wallet. Version 10.10.0 fixes the issue. As a workaround, it is also possible to downgrade to 10.9.1. | |
| Title | Prebid.js NPM package briefly compromised | |
| Weaknesses | CWE-506 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-10T18:02:00.169Z
Reserved: 2025-09-08T16:19:26.171Z
Link: CVE-2025-59038
Updated: 2025-09-10T18:01:49.816Z
Status : Deferred
Published: 2025-09-09T23:15:37.050
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-59038
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA