CVE-2025-59039: Prebid Universal Creative on npm briefly compromised
Impact Npm users of PUC 1.17.3 or PUC latest were briefly affected by crypto-related malware detailed in the blog post below. This includes the extremely popular jsdelivr hosting of this file.
Patches We unpublished the version on npm.
Workarounds This has already been unpublished. See Prebid.js 9 release notes for suggestions on moving off the deprecated workflow of using the PUC or pointing to a dynamic version of it. PUC users pointing to latest should transition to 1.17.2 ASAP to avoid similar attacks in the future.
References https://www.sonatype.com/blog/npm-chalk-and-debug-packages-hit-in-software-supply-chain-attack
Other sources
Prebid Universal Creative (PUC) is a JavaScript API to render multiple formats. Npm users of PUC 1.17.3 or PUC latest were briefly affected by crypto-related malware. This includes the extremely popular jsdelivr hosting of this file. The maintainers of PUC unpublished version 1.17.3. Users should see Prebid.js 9 release notes for suggestions on moving off the deprecated workflow of using the PUC or pointing to a dynamic version of it. PUC users pointing to latest should transition to 1.17.2 as soon as possible to avoid similar attacks in the future.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Prebid Universal Creative (PUC)to a version that resolves this vulnerability.Fixed in 1.17.2 - Compensating control
In npm, avoid using a dynamic tag like “latest” for Prebid Universal Creative (PUC); transition off the deprecated workflow of using PUC or pointing to a dynamic version (per Prebid.js 9 release notes).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59039?
CVE-2025-59039 is categorized as a high-severity vulnerability due to the impact of crypto-related malware affecting Prebid Universal Creative.
How do I fix CVE-2025-59039?
To fix CVE-2025-59039, users should upgrade from Prebid Universal Creative version 1.17.3 to a secure version that does not include the vulnerability.
What software is affected by CVE-2025-59039?
CVE-2025-59039 specifically affects Npm users of Prebid Universal Creative version 1.17.3 and any latest versions around that timeframe.
What kind of malware is associated with CVE-2025-59039?
CVE-2025-59039 is associated with crypto-related malware that impacted users of Prebid Universal Creative.
What should I do if I am using an affected version of Prebid Universal Creative regarding CVE-2025-59039?
If you are using the affected version of Prebid Universal Creative, it is crucial to uninstall the vulnerable version and install a safe version immediately.