CVE Vulnerabilities

CVE-2025-54313

Embedded Malicious Code

Published: Jul 19, 2025 | Modified: Jan 23, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

Weakness

The product contains code that appears to be malicious in nature.

Affected Software

NameVendorStart VersionEnd Version
Eslint-config-prettierPrettier8.10.1 (including)8.10.1 (including)
Eslint-config-prettierPrettier9.1.1 (including)9.1.1 (including)
Eslint-config-prettierPrettier10.1.6 (including)10.1.6 (including)
Eslint-config-prettierPrettier10.1.7 (including)10.1.7 (including)

Potential Mitigations

References