CVE-2025-59331 describes a supply chain attack affecting the 'is-arrayish' npm package, where a compromised publishing account was used to inject malware into version 0.3.3. This malware, targeting cryptocurrency transactions and wallets like MetaMask, specifically impacts browser environments where the package is used. The vulnerability carries a high CVSS score of 8.8 due to its network attack vector and high impact on integrity, though it does not affect local or server environments. While the malicious package was quickly removed from npm, users must update to version 0.3.4, clear caches, and rebuild browser bundles to mitigate the risk, as there is no active exploit intelligence or community discussion reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Qix- | Node-Is-Arrayish | = 0.3.3CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.