Vulnerability Description
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Prettier | Eslint-Config-Prettier | 8.10.1 |
| Microsoft | Windows | - |
| Prettier | Eslint-Plugin-Prettier | 4.2.2 |
| Un-Ts | Synckit | 0.11.9 |
| Un-Ts | Pkgr\/Core | 0.2.8 |
| Alexghr | Got-Fetch | 5.1.1 |
| Un-Ts | Napi-Postinstall | 0.3.1 |
| Homarr | Homarr | >= 1.29.0, < 1.30.0 |
Related Weaknesses (CWE)
References
- https://github.com/prettier/eslint-config-prettier/issues/339Issue Tracking
- https://news.ycombinator.com/item?id=44608811Issue Tracking
- https://news.ycombinator.com/item?id=44609732Issue Tracking
- https://socket.dev/blog/npm-phishing-campaign-leads-to-prettier-tooling-packagesThird Party Advisory
- https://www.bleepingcomputer.com/news/security/popular-npm-linter-packages-hijacExploitThird Party Advisory
- https://www.npmjs.com/package/eslint-config-prettier?activeTab=versionsProduct
- https://www.stepsecurity.io/blog/supply-chain-security-alert-eslint-config-prettExploitThird Party Advisory
- https://github.com/community-scripts/ProxmoxVE/discussions/6115Third Party Advisory
- https://www.endorlabs.com/learn/cve-2025-54313-eslint-config-prettier-compromiseThird Party Advisory
- https://www.bleepingcomputer.com/news/security/popular-npm-linter-packages-hijacExploitThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-US Government Resource
FAQ
What is CVE-2025-54313?
CVE-2025-54313 is a vulnerability with a CVSS score of 7.5 (HIGH). eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gy...
How severe is CVE-2025-54313?
CVE-2025-54313 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-54313?
Check the references section above for vendor advisories and patch information. Affected products include: Prettier Eslint-Config-Prettier, Microsoft Windows, Prettier Eslint-Plugin-Prettier, Un-Ts Synckit, Un-Ts Pkgr\/Core.