Exploit in is-arrayish Library Affects npm Users
CVE-2025-59331

8.8HIGH

Key Information:

Vendor

Qix-

Vendor
CVE Published:
15 September 2025

What is CVE-2025-59331?

The is-arrayish library, widely used in npm projects, was compromised after the account of its maintainer fell victim to a phishing attack. A malicious version, v0.3.3, was subsequently published, embedding a malware payload designed to redirect cryptocurrency transactions, specifically targeting wallet applications like MetaMask. While environments operating outside of browser contexts are unaffected, developers who have included this package in their browser apps or build processes must act quickly. npm has since removed the malicious version and released fixed updates. Users are strongly advised to update to version 0.3.4, clear their development caches, and rebuild any affected bundles to ensure their applications are secure.

Affected Version(s)

node-is-arrayish = 0.3.3

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59331 : Exploit in is-arrayish Library Affects npm Users