Embedded malicious code (backdoor) in eslint-config-prettier - CVE-2025-54313
Published: July 23, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to the application.
The vulnerability exists due to presence of embedded malicious code in the application caused by maintainer account compromise on July 18. A remote attacker can compromise the affected system.
Reportedly the issue affects Microsoft Windows installations only.
Affected software
DB2 Data Management Console
IBM Watson Discovery for IBM Cloud Pak for Data
How to mitigate CVE-2025-54313
DB2 Data Management Console - update to 3.1.13.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.2.1
External References
- https://github.com/community-scripts/ProxmoxVE/discussions/6115
- https://github.com/prettier/eslint-config-prettier/issues/339
- https://news.ycombinator.com/item?id=44608811
- https://news.ycombinator.com/item?id=44609732
- https://socket.dev/blog/npm-phishing-campaign-leads-to-prettier-tooling-packages-compromise
- https://www.bleepingcomputer.com/news/security/popular-npm-linter-packages-hijacked-via-phishing-to-drop-malware/
- https://www.endorlabs.com/learn/cve-2025-54313-eslint-config-prettier-compromise----high-severity-but-windows-only
- https://www.npmjs.com/package/eslint-config-prettier?activeTab=versions
- https://www.stepsecurity.io/blog/supply-chain-security-alert-eslint-config-prettier-package-shows-signs-of-compromise