Exploit in is-arrayish Library Affects npm Users
CVE-2025-59331
What is CVE-2025-59331?
The is-arrayish library, widely used in npm projects, was compromised after the account of its maintainer fell victim to a phishing attack. A malicious version, v0.3.3, was subsequently published, embedding a malware payload designed to redirect cryptocurrency transactions, specifically targeting wallet applications like MetaMask. While environments operating outside of browser contexts are unaffected, developers who have included this package in their browser apps or build processes must act quickly. npm has since removed the malicious version and released fixed updates. Users are strongly advised to update to version 0.3.4, clear their development caches, and rebuild any affected bundles to ensure their applications are secure.
Affected Version(s)
node-is-arrayish = 0.3.3