Malware-Laden Package Found in error-ex by Qix
CVE-2025-59330

8.8HIGH

Key Information:

Vendor

Qix-

Vendor
CVE Published:
15 September 2025

What is CVE-2025-59330?

The error-ex package by Qix faced a significant security breach when an npm account was compromised due to a phishing attack. On September 8, 2025, version 1.3.3 was published, which, although functionally similar to its predecessor, contained malware designed to redirect cryptocurrency transactions towards the attacker's wallets when used within web environments. While local and server environments remained safe, the exposure of cryptocurrency wallets like MetaMask to this malicious code poses a risk to developers and users relying on the error-ex package for browser-based applications. To mitigate risks, users are recommended to upgrade to the latest patch version, delete the current node_modules directory, clear their package manager caches, and rebuild any web application bundles. Furthermore, administrators of private registries should ensure all compromised versions are purged from their caches.

Affected Version(s)

node-error-ex = 1.3.3

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59330 : Malware-Laden Package Found in error-ex by Qix