Vulnerabilities/

[email protected] contains malware after npm account takeover

Severity:
High

Description

On 8 September 2025, the npm publishing account for debug was taken over after a phishing attack. Version 4.4.2 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker’s own addresses from within browser environments.

Recommendation

Update the debug package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
debug
Anything's wrong? Let us know Last updated on September 15, 2025

This issue is available in SmartScanner Professional

See Pricing