SB2026042468 - Embedded malicious code (backdoor) in debug
Published: April 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Embedded malicious code (backdoor) (CVE-ID: CVE-2025-59144)
The vulnerability allows a remote attacker to redirect cryptocurrency transactions to attacker-controlled addresses.
The vulnerability exists due to embedded malicious code in the debug package when the package is executed in a browser context. A remote attacker can publish a compromised package version to redirect cryptocurrency transactions to attacker-controlled addresses.
The malicious payload only affects browser environments and appears to target cryptocurrency wallets and transactions.
Remediation
Install update from vendor's website.