296,480
Total vulnerabilities in the database
This advisory only applies to developers who use MetaMask SDK in the browser and who, on Sept 8th 2025 between 13:00–15:30 UTC, performed one of the following actions and then deployed their application:
debug@4.4.2
(e.g., via npm update
or yarn upgrade
)On Sept 8th, 2025 (13:00–15:30 UTC), a malicious version of the debug
package (v4.4.2) was published to npm. The injected code attempts to interfere with dApp-to-wallet communication when executed in a browser context.
While MetaMask SDK itself was not directly impacted, projects installing the SDK during this window may have inadvertently pulled in the malicious version of debug
.
debug@4.4.2
.node_modules
and reinstall dependencies before deploying.Software | From | Fixed in |
---|---|---|
![]() |
0.16.0 | 0.33.1 |
![]() |
0.16.0 | 0.33.1 |
![]() |
0.16.0 | 0.33.1 |