CVE-2025-59039: Prebid Universal Creative on npm briefly compromised

Published Sep 9, 2025
·
Updated

Impact Npm users of PUC 1.17.3 or PUC latest were briefly affected by crypto-related malware detailed in the blog post below. This includes the extremely popular jsdelivr hosting of this file.

Patches We unpublished the version on npm.

Workarounds This has already been unpublished. See Prebid.js 9 release notes for suggestions on moving off the deprecated workflow of using the PUC or pointing to a dynamic version of it. PUC users pointing to latest should transition to 1.17.2 ASAP to avoid similar attacks in the future.

References https://www.sonatype.com/blog/npm-chalk-and-debug-packages-hit-in-software-supply-chain-attack

Other sources

Prebid Universal Creative (PUC) is a JavaScript API to render multiple formats. Npm users of PUC 1.17.3 or PUC latest were briefly affected by crypto-related malware. This includes the extremely popular jsdelivr hosting of this file. The maintainers of PUC unpublished version 1.17.3. Users should see Prebid.js 9 release notes for suggestions on moving off the deprecated workflow of using the PUC or pointing to a dynamic version of it. PUC users pointing to latest should transition to 1.17.2 as soon as possible to avoid similar attacks in the future.

MITRE

Affected Software

3 affected components
prebid Universal Creative=1.17.3
prebid Universal Creative<1.17.3
npm/prebid-universal-creative=1.17.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Prebid Universal Creative (PUC) to a version that resolves this vulnerability.

    Fixed in 1.17.2
  2. Compensating control

    In npm, avoid using a dynamic tag like “latest” for Prebid Universal Creative (PUC); transition off the deprecated workflow of using PUC or pointing to a dynamic version (per Prebid.js 9 release notes).

Event History

Sep 9, 2025
CVE Published
via MITRE·10:23 PM
Data Sourced
via MITRE·10:23 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Sep 11, 2025
Advisory Published
via GitHub·02:24 PM
Data Sourced
via GitHub·02:24 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-59039?

CVE-2025-59039 is categorized as a high-severity vulnerability due to the impact of crypto-related malware affecting Prebid Universal Creative.

2

How do I fix CVE-2025-59039?

To fix CVE-2025-59039, users should upgrade from Prebid Universal Creative version 1.17.3 to a secure version that does not include the vulnerability.

3

What software is affected by CVE-2025-59039?

CVE-2025-59039 specifically affects Npm users of Prebid Universal Creative version 1.17.3 and any latest versions around that timeframe.

4

What kind of malware is associated with CVE-2025-59039?

CVE-2025-59039 is associated with crypto-related malware that impacted users of Prebid Universal Creative.

5

What should I do if I am using an affected version of Prebid Universal Creative regarding CVE-2025-59039?

If you are using the affected version of Prebid Universal Creative, it is crucial to uninstall the vulnerable version and install a safe version immediately.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203