LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-54313: Prettier eslint-config-prettier Embedded Malicious Code Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 22, 2026
CVSS 7.5 · High⚠ Actively exploited (CISA KEV)
7.5
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 12, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-54313 to its Known Exploited Vulnerabilities catalog on Jan 22, 2026, with a federal patch deadline of Feb 12, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

This vulnerability affects the eslint-config-prettier package used with Prettier in JavaScript projects. It stems from embedded malicious code that runs automatically during package installation on Windows systems, executing an install.js script that launches node-gyp.dll malware. The issue matters because development environments often pull dependencies without deep inspection, allowing supply-chain compromise to occur silently during routine npm or yarn operations.

How it works

The weakness is classified as CWE-506, embedded malicious code. An attacker places the malicious payload inside the published package so that the package manager's standard install lifecycle triggers execution. On Windows, the install.js file runs and starts node-gyp.dll. No further attacker interaction is required after the initial package installation.

Am I affected? How to find it in your systems

How to remediate

Apply the vendor-supplied update referenced in the official advisory. After patching, remove any previously installed affected packages and clear associated cache directories. For this class of supply-chain weakness, organizations should also enforce package-integrity verification through lockfile enforcement and restrict installation sources to trusted registries.

If you can't patch immediately

If your data may have been exposed

Actively exploited vulnerabilities of this type have led to data breaches. You can run a free exposure scan of your email addresses against known breach datasets to check for prior compromise.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedPrettier · eslint-config-prettier
WeaknessCWE-506
CVSS base score7.5 (High)
CVSS vectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
PublishedJul 19, 2025
Added to CISA KEVJan 22, 2026
Federal patch deadlineFeb 12, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities