prebid-universal-creative

npm Compromised

1

report

Attack type: Other

Reports

Other CVE-2025-59039 Versions: = 1.17.3 217d ago by isitcompromised.com

Prebid-universal-creative latest on npm briefly compromised ### Impact Npm users of PUC 1.17.3 or PUC latest were briefly affected by crypto-related malware detailed in the blog post below. This includes the extremely popular jsdelivr hosting of this file. ### Patches We unpublished the version on npm. ### Workarounds This has already been unpublished. See Prebid.js 9 release notes for suggestions on moving off the deprecated workflow of using the PUC or pointing to a dynamic version of it. PUC users pointing to latest should transition to 1.17.2 ASAP

View evidence

Have more info?

Submit additional evidence or a new report for this package.

Submit a report