


Perceptive Security
SOC/SIEM Consultancy

Supply Chain Security Alert: eslint-config-prettier Package Shows Signs of Compromise
Published:
5 december 2025 om 11:50:29
Alert date:
5 december 2025 om 12:01:17
Source:
stepsecurity.io

StepSecurity is investigating a potential supply chain security incident involving the eslint-config-prettier npm package. The widely-used package, which helps developers maintain consistent code formatting by turning off ESLint rules that conflict with Prettier, appears to have had multiple versions published with suspicious modifications. This represents a significant supply chain risk given the package's widespread adoption in JavaScript development environments. The compromise could potentially affect numerous downstream projects that depend on this popular configuration package.
Technical details
Mitigation steps:
Affected products:
eslint-config-prettier
npm
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.