Description
Prebid Universal Creative (PUC) is a JavaScript API to render multiple formats. Npm users of PUC 1.17.3 or PUC latest were briefly affected by crypto-related malware. This includes the extremely popular jsdelivr hosting of this file. The maintainers of PUC unpublished version 1.17.3. Users should see Prebid.js 9 release notes for suggestions on moving off the deprecated workflow of using the PUC or pointing to a dynamic version of it. PUC users pointing to latest should transition to 1.17.2 as soon as possible to avoid similar attacks in the future.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27597 | Prebid-universal-creative latest on npm briefly compromised |
Github GHSA |
GHSA-m662-56rj-8fmm | Prebid-universal-creative latest on npm briefly compromised |
References
History
Wed, 10 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Sep 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Prebid Universal Creative (PUC) is a JavaScript API to render multiple formats. Npm users of PUC 1.17.3 or PUC latest were briefly affected by crypto-related malware. This includes the extremely popular jsdelivr hosting of this file. The maintainers of PUC unpublished version 1.17.3. Users should see Prebid.js 9 release notes for suggestions on moving off the deprecated workflow of using the PUC or pointing to a dynamic version of it. PUC users pointing to latest should transition to 1.17.2 as soon as possible to avoid similar attacks in the future. | |
| Title | Prebid Universal Creative on npm briefly compromised | |
| Weaknesses | CWE-506 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-10T18:00:27.573Z
Reserved: 2025-09-08T16:19:26.171Z
Link: CVE-2025-59039
Updated: 2025-09-10T18:00:21.072Z
Status : Deferred
Published: 2025-09-09T23:15:37.227
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-59039
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA