CVE-2025-54313: Prettier eslint-config-prettier Embedded Malicious Code Vulnerability

High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2026-01-22. EPSS: 4.9% chance of exploitation in the next 30 days.

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

Affected products

  • Alexghr Got-Fetch: version 5.1.1 only; version 5.1.2 only
  • Homarr Homarr: from 1.29.0, before 1.30.0 (fixed in 1.30.0)
  • Prettier eslint-config-prettier: version 8.10.1 only; version 9.1.1 only; version 10.1.6 only; version 10.1.7 only
  • Prettier Eslint-Plugin-Prettier: version 4.2.2 only; version 4.2.3 only
  • Un-Ts Napi-Postinstall: version 0.3.1 only
  • Un-Ts Pkgr/core: version 0.2.8 only
  • Un-Ts Synckit: version 0.11.9 only

Published 2025-07-19. Last modified 2026-06-17.