HIGH

CVE-2025-54313

Prettier Eslint Config Prettier 2025-07-19 CVSS v3.1
CVSS
7.5
KEV

Description

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

Summary dbcve.org

eslint-config-prettier versions 8.10.1, 9.1.1, 10.1.6, and 10.1.7 were compromised with a supply chain attack. The malicious install.js script executes during npm install and drops the node-gyp.dll malware specifically targeting Windows systems.

Mitigation

Immediately audit systems for presence of affected versions and remove them. Reinstall eslint-config-prettier from known-good versions (preferably 10.2.0+ or earlier safe versions like 8.x and 9.x) and scan Windows machines for indicators of compromise.

Proof of Concept

Weakness (CWE)

CWE-506

EPSS Score

4.52%
Probability of exploitation in next 30 days
91.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE