CVE Details
Basic Information
| Title | CVE-2025-54313 |
|---|---|
| Type | cve |
| Published | 2025-07-19T00:00:00.000Z |
| Modified | 2025-07-19T16:43:13.088Z |
Product Information
| Vendor | prettier |
|---|---|
| Product | eslint-config-prettier |
| Version | 8.10.1 |
CVSS Information
| Base Score | 7.5 (HIGH) |
|---|---|
| Attack Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N |
Affected Products
- prettier eslint-config-prettier 8.10.1
- prettier eslint-config-prettier 9.1.1
- prettier eslint-config-prettier 10.1.6
- prettier eslint-config-prettier 10.1.7
Additional Information
| CWE List | CWE-506 |
|---|---|
| Source | mitre |
Description
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
References
- https://socket.dev/blog/npm-phishing-campaign-leads-to-prettier-tooling-packages-compromise
- https://www.bleepingcomputer.com/news/security/popular-npm-linter-packages-hijacked-via-phishing-to-drop-malware/
- https://github.com/prettier/eslint-config-prettier/issues/339
- https://www.npmjs.com/package/eslint-config-prettier?activeTab=versions
- https://www.stepsecurity.io/blog/supply-chain-security-alert-eslint-config-prettier-package-shows-signs-of-compromise
- https://news.ycombinator.com/item?id=44609732
- https://news.ycombinator.com/item?id=44608811