PT-2025-37742 · Npm · Backslash

Informatic

·

Published

2025-09-08

·

Updated

2025-09-20

·

CVE-2025-59140

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red
Name of the Vulnerable Software and Affected Versions backslash versions prior to 0.2.2
Description The backslash npm package was compromised through a phishing attack on the publishing account. Version 0.2.1 was published with a malicious payload designed to redirect cryptocurrency transactions from browser environments to the attacker's addresses. Environments not utilizing the package in a browser context, such as local, server, and command-line applications, are not affected. The malware specifically targets cryptocurrency transactions and wallets like MetaMask. The malicious package was removed from the npm registry on September 8, 2025, and new patch versions were published on September 13, 2025, to address caching issues in private registries.
Recommendations Upgrade to version 0.2.2 or later. Completely remove the node modules directory. Clean the package manager's global cache. Rebuild any browser bundles from scratch. Purge the compromised versions from caches on private registries or registry mirrors.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-59140
GHSA-53MQ-F4W3-F7QV
GHSA-M2XF-JP99-F298
MAL-2025-46968

Affected Products

Backslash