We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-54313



Description

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

Reserved 2025-07-19 | Published 2025-07-19 | Updated 2025-07-19 | Assigner mitre


HIGH: 7.5CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N

Problem types

CWE-506 Embedded Malicious Code

Product status

Default status
unaffected

8.10.1
affected

9.1.1
affected

10.1.6
affected

10.1.7
affected

References

socket.dev/...-leads-to-prettier-tooling-packages-compromise

www.bleepingcomputer.com/...ed-via-phishing-to-drop-malware/

github.com/prettier/eslint-config-prettier/issues/339

www.npmjs.com/...e/eslint-config-prettier?activeTab=versions

www.stepsecurity.io/...ier-package-shows-signs-of-compromise

news.ycombinator.com/item?id=44609732

news.ycombinator.com/item?id=44608811

cve.org (CVE-2025-54313)

nvd.nist.gov (CVE-2025-54313)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-54313

Support options

Helpdesk Chat, Email, Knowledgebase