The eslint-config-prettier npm Supply Chain Attack

Updated 5 Oct 2026 · Incident date 18 Jul 2025 · npm

Packageeslint-config-prettier 8.10.0/9.1.0/10.1.5 -> 8.10.1, 9.1.1, 10.1.6, 10.1.7 (also eslint-plugin-prettier, synckit, @pkgr/core, napi-postinstall)
Fileinstall.js

On 18 July 2025, attackers published eslint-config-prettier 8.10.1, 9.1.1, 10.1.6 and 10.1.7 to npm. Each version carries an install script that runs a hidden DLL on Windows. The issue has the identifier CVE-2025-54313.

A phishing email gave the attackers a maintainer's npm token. They also published bad versions of four related packages.

What happened

A phishing email tricked a maintainer, and the attackers used the stolen npm token to publish bad releases. StepSecurity quotes the maintainer from 18 July 2025. He said that a phishing email tricked him and that a new npm token was added and leaked.

Socket says the attackers used the look-alike domain npnjs.com to collect credentials. A GitHub issue showed that four new versions of eslint-config-prettier had no matching commits or pull requests in the source repository.

The package holds only configuration. It has no reason to run code at install time. The bad versions gained an install.js file and an install hook. The code checks for Windows and then runs a file named node-gyp.dll through rundll32. The Snyk advisory says the code tries to run the payload in that DLL, and that the payload is a known trojan with VirusTotal signatures. The code does nothing on other systems.

The campaign grew. StepSecurity reports bad releases of two more packages, is and got-fetch, through the same kind of phishing. It says the got-fetch variant installed an information stealer called Pycoon through a file named crashreporter.dll.

The maintainers deprecated the bad versions and published clean replacements. Snyk lists the fixed releases as 8.10.2, 9.1.2 and 10.1.8.

Affected versions

Socket lists these bad versions.

StepSecurity also lists is 3.3.1 and 5.0.0, and got-fetch 5.1.11 and 5.1.12.

Fixed versions of eslint-config-prettier are 8.10.2, 9.1.2 and 10.1.8 or higher. Socket says 10.1.5 and earlier are safe.

Indicators of compromise

How to check

List the installed versions of all five packages and look for an install script in the config package.

npm ls --all eslint-config-prettier eslint-plugin-prettier synckit @pkgr/core napi-postinstall
find node_modules -path '*eslint-config-prettier/install.js'
grep -n 'node-gyp.dll' -r node_modules/eslint-config-prettier

The package has no install.js in clean versions, so a hit on the second command is a finding. Check CI logs and automatic upgrade pull requests from 18 July 2025 as well.

What to do now

  1. Pin eslint-config-prettier to a clean or fixed version. Pin the other four packages away from the bad versions.
  2. Delete node_modules, clear the npm cache and reinstall from a clean lockfile.
  3. If a Windows machine or build ran a bad install, treat it as compromised. Rotate credentials that it held.
  4. Audit CI logs and dependency bot pull requests that installed these versions.
  5. Turn on two-factor authentication on npm accounts and pin exact versions in CI.
  6. Vigilance compares a new package version with the one you trust and reports the file that gained a new capability. Here, a config-only package gained an install script and a hook that runs a DLL.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old eslint-config-prettier-prev --new eslint-config-prettier-current
files scanned: 45 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   install.js
           It runs a command on its own when it is installed, downloads from the internet and runs other programs.

Frequently asked questions

Which eslint-config-prettier versions were compromised?

Versions 8.10.1, 9.1.1, 10.1.6 and 10.1.7. Fixed versions are 8.10.2, 9.1.2 and 10.1.8 or higher.

What did the compromised eslint-config-prettier do?

The bad versions added an install script that runs node-gyp.dll through rundll32 on Windows. Snyk says the DLL holds a known trojan.

What is CVE-2025-54313?

It is the identifier for the eslint-config-prettier compromise, where phishing led to malicious versions that try to run a payload in node-gyp.dll on Windows.

Which other packages were affected with eslint-config-prettier?

Socket lists eslint-plugin-prettier 4.2.2 and 4.2.3, synckit 0.11.9, @pkgr/core 0.2.8 and napi-postinstall 0.3.1.

Sources

  1. socket.dev/blog/npm-phishing-campaign-leads-to-prettier-tooling-packages-compromise
  2. stepsecurity.io/blog/supply-chain-security-alert-eslint-config-prettier-package-shows-signs-of-compromise
  3. security.snyk.io/vuln/SNYK-JS-ESLINTCONFIGPRETTIER-10873299

More supply chain attacks

All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free