
We found results for “”
MSC-2025-7951
Good to know:

Date: September 10, 2025
prebid was compromised to include malicious code that targets browser-based web3 environments. The injected payload intercepts Ethereum and Solana wallet interactions, redirecting funds and approvals to attacker-controlled addresses. The compromise occurred after a maintainer’s account was accessed via phishing. At the moment, there is no fix version. We recommend removing the affected version from the codebase Reference: https://www.mend.io/blog/npm-supply-chain-attack-infiltrates-popular-packages/
Language: JS
Severity Score
Severity Score
Weakness Type (CWE)
Hidden Functionality
CWE-912CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |