DuckDB is an analytical in-process SQL database management system. On 08 September 2025, the DuckDB distribution for Node.js on npm was compromised with malware (along with several other packages). An attacker published new versions of four of DuckDB's packages that included malicious code to interfere with cryptocoin transactions* According to the npm statistics, nobody has downloaded these packages before they were deprecated. The packages and versions `@duckdb/node-api@1.3.3`, `@duckdb/node-bindings@1.3.3`, `duckdb@1.3.3`, and `@duckdb/duckdb-wasm@1.29.2` were affected. DuckDB immediately deprecated the specific versions, engaged npm support to delete the affected verions, and re-released the node packages with higher version numbers (1.3.4/1.30.0). Users may upgrade to versions 1.3.4, 1.30.0, or a higher version to protect themselves. As a workaround, they may also downgrade to 1.3.2 or 1.29.1.
History

Wed, 24 Sep 2025 00:15:00 +0000


Fri, 12 Sep 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Duckdb
Duckdb duckdb
Vendors & Products Duckdb
Duckdb duckdb

Wed, 10 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Sep 2025 20:45:00 +0000

Type Values Removed Values Added
Description DuckDB is an analytical in-process SQL database management system. On 08 September 2025, the DuckDB distribution for Node.js on npm was compromised with malware (along with several other packages). An attacker published new versions of four of DuckDB's packages that included malicious code to interfere with cryptocoin transactions* According to the npm statistics, nobody has downloaded these packages before they were deprecated. The packages and versions `@duckdb/node-api@1.3.3`, `@duckdb/node-bindings@1.3.3`, `duckdb@1.3.3`, and `@duckdb/duckdb-wasm@1.29.2` were affected. DuckDB immediately deprecated the specific versions, engaged npm support to delete the affected verions, and re-released the node packages with higher version numbers (1.3.4/1.30.0). Users may upgrade to versions 1.3.4, 1.30.0, or a higher version to protect themselves. As a workaround, they may also downgrade to 1.3.2 or 1.29.1.
Title DuckDB NPM packages 1.3.3 and 1.29.2 briefly compromised with malware
Weaknesses CWE-506
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-09-09T20:26:57.986Z

Updated: 2025-09-10T14:28:58.864Z

Reserved: 2025-09-08T16:19:26.171Z

Link: CVE-2025-59037

cve-icon Vulnrichment

Updated: 2025-09-10T14:04:04.776Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-09T21:15:39.170

Modified: 2025-09-11T17:14:25.240

Link: CVE-2025-59037

cve-icon Redhat

Severity : Important

Publid Date: 2025-09-09T20:26:57Z

Links: CVE-2025-59037 - Bugzilla