GHSA-4x49-vf9v-38px
HIGHCVE-2025-59144On 8 September 2025, the npm publishing account for debug was taken over after a phishing attack. Version 4.4.2 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments.
- Affected
- = 4.4.2
- Fixed in
- 4.4.3
- Weakness
- CWE-506
- Published
- 2025-09-15
- Source
- github