CVE-2025-54313: Prettier eslint-config-prettier Embedded Malicious Code Vulnerability
High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2026-01-22. EPSS: 4.9% chance of exploitation in the next 30 days.
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
Affected products
- Alexghr Got-Fetch: version 5.1.1 only; version 5.1.2 only
- Homarr Homarr: from 1.29.0, before 1.30.0 (fixed in 1.30.0)
- Prettier eslint-config-prettier: version 8.10.1 only; version 9.1.1 only; version 10.1.6 only; version 10.1.7 only
- Prettier Eslint-Plugin-Prettier: version 4.2.2 only; version 4.2.3 only
- Un-Ts Napi-Postinstall: version 0.3.1 only
- Un-Ts Pkgr/core: version 0.2.8 only
- Un-Ts Synckit: version 0.11.9 only
Published 2025-07-19. Last modified 2026-06-17.