Home

Description

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

PUBLISHED Reserved 2025-07-19 | Published 2025-07-19 | Updated 2026-01-22 | Assigner mitre




HIGH: 7.5CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N

CISA Known Exploited Vulnerability

Date added 2026-01-22 | Due date 2026-02-12

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Problem types

CWE-506 Embedded Malicious Code

Product status

Default status
unaffected

8.10.1 (semver)
affected

9.1.1 (semver)
affected

10.1.6 (semver)
affected

10.1.7 (semver)
affected

References

github.com/community-scripts/ProxmoxVE/discussions/6115

www.endorlabs.com/...omise----high-severity-but-windows-only

www.bleepingcomputer.com/...ed-via-phishing-to-drop-malware/ exploit

www.cisa.gov/...erabilities-catalog?field_cve=CVE-2025-54313 government-resource

socket.dev/...-leads-to-prettier-tooling-packages-compromise

www.bleepingcomputer.com/...ed-via-phishing-to-drop-malware/

github.com/prettier/eslint-config-prettier/issues/339

www.npmjs.com/...e/eslint-config-prettier?activeTab=versions

www.stepsecurity.io/...ier-package-shows-signs-of-compromise

news.ycombinator.com/item?id=44609732

news.ycombinator.com/item?id=44608811

cve.org (CVE-2025-54313)

nvd.nist.gov (CVE-2025-54313)

Download JSON