296,746
Total vulnerabilities in the database
This advisory only applies to developers who use MetaMask SDK in the browser and who, on Sept 8th 2025 between 13:00–15:30 UTC, performed one of the following actions and then deployed their application:
debug@4.4.2 (e.g., via npm update or yarn upgrade)On Sept 8th, 2025 (13:00–15:30 UTC), a malicious version of the debug package (v4.4.2) was published to npm. The injected code attempts to interfere with dApp-to-wallet communication when executed in a browser context.
While MetaMask SDK itself was not directly impacted, projects installing the SDK during this window may have inadvertently pulled in the malicious version of debug.
debug@4.4.2.node_modules and reinstall dependencies before deploying.| Software | From | Fixed in |
|---|---|---|
@metamask / sdk
|
0.16.0 | 0.33.1 |
@metamask / sdk-react
|
0.16.0 | 0.33.1 |
@metamask / sdk-communication-layer
|
0.16.0 | 0.33.1 |