Malware-Laden Package Found in error-ex by Qix
CVE-2025-59330
What is CVE-2025-59330?
The error-ex package by Qix faced a significant security breach when an npm account was compromised due to a phishing attack. On September 8, 2025, version 1.3.3 was published, which, although functionally similar to its predecessor, contained malware designed to redirect cryptocurrency transactions towards the attacker's wallets when used within web environments. While local and server environments remained safe, the exposure of cryptocurrency wallets like MetaMask to this malicious code poses a risk to developers and users relying on the error-ex package for browser-based applications. To mitigate risks, users are recommended to upgrade to the latest patch version, delete the current node_modules directory, clear their package manager caches, and rebuild any web application bundles. Furthermore, administrators of private registries should ensure all compromised versions are purged from their caches.
Affected Version(s)
node-error-ex = 1.3.3