MAL-2025-47026

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/prebid/MAL-2025-47026.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-47026
Published
2025-09-11T03:58:52Z
Modified
2025-09-26T11:06:45Z
Summary
Malicious code in prebid (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: google-open-source-security (14e7380eb0ee7e6be1b7896f1a961c6f7282199fcce42017c4003fc73695ee52)

This package was compromised and malicious code added as part of a phishing campaign.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "14e7380eb0ee7e6be1b7896f1a961c6f7282199fcce42017c4003fc73695ee52",
            "source": "google-open-source-security",
            "modified_time": "2025-09-11T03:58:52Z",
            "versions": [
                "10.9.2",
                "10.9.1"
            ],
            "import_time": "2025-09-11T03:59:18.944527Z"
        },
        {
            "sha256": "cb5864309ee640c7174dbb6cccfc47f6ef2b2d2c94914b09a0c5d14da13179a3",
            "source": "reversing-labs",
            "modified_time": "2025-09-26T09:40:05Z",
            "id": "RLMA-2025-05128",
            "versions": [
                "10.9.1",
                "10.9.2"
            ],
            "import_time": "2025-09-26T11:06:01.863061792Z"
        }
    ]
}
References
Credits

Affected packages

npm / prebid

Package

Affected ranges

Affected versions

10.*
10.9.1
10.9.2

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/prebid/MAL-2025-47026.json"