Embedded malicious code (backdoor) in debug - CVE-2025-59144
Published: April 24, 2026
debug
Detailed vulnerability description
The vulnerability allows a remote attacker to redirect cryptocurrency transactions to attacker-controlled addresses.
The vulnerability exists due to embedded malicious code in the debug package when the package is executed in a browser context. A remote attacker can publish a compromised package version to redirect cryptocurrency transactions to attacker-controlled addresses.
The malicious payload only affects browser environments and appears to target cryptocurrency wallets and transactions.