Description

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

INFO

Published Date :

2025-07-19T00:00:00.000Z

Last Modified :

2026-02-26T17:50:26.767Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-54313 vulnerability.

Vendors Products
Alexghr
  • Got-fetch
Homarr
  • Homarr
Microsoft
  • Windows
Prettier
  • Eslint-config-prettier
  • Eslint-plugin-prettier
Un-ts
  • Napi-postinstall
  • Pkgr\/core
  • Synckit

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact