CVE-2025-59142

Source
https://cve.org/CVERecord?id=CVE-2025-59142
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59142.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-59142
Aliases
Published
2025-09-15T19:10:07Z
Modified
2026-09-03T11:45:28Z
Severity
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:A/U:Red CVSS Calculator
Summary
color-string@2.1.1 contains malware after npm account takeover
Details

color-string is a parser and generator for CSS color strings. On 8 September 2025, the npm publishing account for color-string was taken over after a phishing attack. Version 2.1.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local environments, server environments, command line applications, etc. are not affected. If the package was used in a browser context (e.g. a direct

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-506"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/59xxx/CVE-2025-59142.json"
}
References

Affected packages

Git / github.com/debug-js/debug

Affected ranges

Type
GIT
Repo
https://github.com/debug-js/debug
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "= 2.1.1"
        },
        {
            "last_affected": "= 2.1.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

= 2.*
= 2.1.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59142.json"