Description
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
CISA Known Exploited Vulnerability
Date added 2026-01-22 | Due date 2026-02-12
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Problem types
CWE-506 Embedded Malicious Code
Product status
8.10.1 (semver)
9.1.1 (semver)
10.1.6 (semver)
10.1.7 (semver)
References
github.com/community-scripts/ProxmoxVE/discussions/6115
www.endorlabs.com/...omise----high-severity-but-windows-only
www.bleepingcomputer.com/...ed-via-phishing-to-drop-malware/
www.cisa.gov/...erabilities-catalog?field_cve=CVE-2025-54313
socket.dev/...-leads-to-prettier-tooling-packages-compromise
www.bleepingcomputer.com/...ed-via-phishing-to-drop-malware/
github.com/prettier/eslint-config-prettier/issues/339
www.npmjs.com/...e/eslint-config-prettier?activeTab=versions
www.stepsecurity.io/...ier-package-shows-signs-of-compromise
news.ycombinator.com/item?id=44609732
news.ycombinator.com/item?id=44608811