PT-2025-37746 · Npm · Debug

Charlie Eriksen

·

Published

2025-09-08

·

Updated

2025-09-30

·

CVE-2025-59144

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red
Name of the Vulnerable Software and Affected Versions debug versions 4.4.2
Description The npm publishing account for debug was compromised following a phishing attack on September 8, 2025. Version 4.4.2 was published with a malicious payload designed to redirect cryptocurrency transactions within browser environments. Environments not utilizing the package in a browser context, such as local, server, or command-line applications, are not affected. The malware specifically targets cryptocurrency transactions and wallets like MetaMask.
Recommendations Upgrade to the latest patch version, completely remove the node modules directory, clean the package manager's global cache, and rebuild any browser bundles. Those operating private registries or registry mirrors should purge the compromised versions from any caches. If suspicious behavior persists after performing these steps, contact the package owner via Bluesky at https://bsky.app/profile/bad-at-computer.bsky.social or through the tracking issue on the debug repository at https://github.com/debug-js/debug/issues/1005.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2026-00374
CVE-2025-59144
GHSA-4X49-VF9V-38PX
GHSA-8MGJ-VMR8-FRR6
MAL-2025-46974

Affected Products

Debug