CVE-2025-54313: Prettier eslint-config-prettier Embedded Malicious Code Vulnerability
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
Other sources
Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/got-fetchto a version that resolves this vulnerability.Fixed in 6.0.0 - Upgrade
Upgrade
npm/napi-postinstallto a version that resolves this vulnerability.Fixed in 0.3.2 - Upgrade
Upgrade
npm/@pkgr/coreto a version that resolves this vulnerability.Fixed in 0.2.9 - Upgrade
Upgrade
npm/synckitto a version that resolves this vulnerability.Fixed in 0.11.10 - Upgrade
Upgrade
npm/eslint-plugin-prettierto a version that resolves this vulnerability.Fixed in 4.2.4 - Upgrade
Upgrade
npm/eslint-config-prettierto a version that resolves this vulnerability.Fixed in 10.1.8 - Upgrade
Upgrade
npm/eslint-config-prettierto a version that resolves this vulnerability.Fixed in 9.1.2 - Upgrade
Upgrade
npm/eslint-config-prettierto a version that resolves this vulnerability.Fixed in 8.10.2 - Compensating control
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54313?
CVE-2025-54313 is classified as a critical vulnerability due to the execution of malware upon installation.
How do I fix CVE-2025-54313?
To fix CVE-2025-54313, you should update to a version of eslint-config-prettier that is beyond 10.1.8.
What versions are affected by CVE-2025-54313?
CVE-2025-54313 affects versions 8.10.1, 9.1.1, 10.1.6, and 10.1.7 of eslint-config-prettier.
What type of malware is involved in CVE-2025-54313?
CVE-2025-54313 involves the installation of node-gyp.dll malware on Windows systems.
How was the CVE-2025-54313 vulnerability introduced?
CVE-2025-54313 was introduced through a supply chain compromise where malicious code was embedded in the package.